Directory Traversal Vulnerability in Hyland OnBase Affected Versions
CVE-2020-25247

7.5HIGH

Key Information:

Vendor

Hyland

Status
Vendor
CVE Published:
11 September 2020

What is CVE-2020-25247?

A directory traversal vulnerability has been identified in Hyland OnBase that permits unauthorized file writing. This flaw impacts OnBase versions up to 18.0.0.32 and 19.x up to 19.8.9.1000. Attackers can exploit the vulnerability through the FileName parameter, potentially leading to unapproved access and manipulation of files located on the server. Appropriate security measures should be implemented to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.