Path Traversal Vulnerability in Marvell QConvergeConsole GUI
CVE-2020-5804
8.1HIGH
What is CVE-2020-5804?
A path traversal vulnerability exists in the Marvell QConvergeConsole GUI versions 5.5.0.74 and earlier. This issue occurs in the deleteEventLogFile method of the GWTTestServiceImpl class, where inadequate validation of user-supplied paths enables an authenticated, remote attacker to delete arbitrary files on the server. Exploiting this flaw grants attackers potential SYSTEM or root privileges, allowing unauthorized file manipulation.
Affected Version(s)
Marvell QConvergeConsole GUI 5.5.0.74