CVE

CVE-2020-5237

CVE-2020-5237

oneup/uploader-bundle before 1.9.3 and 2.1.5, can be exploited to upload files to arbitrary folders on the filesystem. The assembly process can further be misused with some restrictions to delete and copy files to other locations. This is fixed in versions 1.9.3 and 2.1.5.

Source: CVE-2020-5237

Exit mobile version