anySign directory traversal vulnerability
CVE-2020-7882
7.5HIGH
Key Information:
- Vendor
Hancomwith
- Status
- Vendor
- CVE Published:
- 22 November 2021
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2020-7882?
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Affected Version(s)
anySign4PC Windows 1.1.1.0
anySign4PC Windows 1.1.2.6
anySign4PC Windows 1.1.2.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
