Vulnerability Description
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Playtube | Playtube | 1.8 |
Related Weaknesses (CWE)
References
- https://blog.overfl0wed.com/web/lfi/info_disclosure/2020/03/30/PlayTube-LFI-to-IExploitThird Party Advisory
- https://blog.overfl0wed.com/web/lfi/info_disclosure/2020/03/30/PlayTube-LFI-to-IExploitThird Party Advisory
FAQ
What is CVE-2020-13792?
CVE-2020-13792 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.
How severe is CVE-2020-13792?
CVE-2020-13792 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13792?
Check the references section above for vendor advisories and patch information. Affected products include: Playtube Playtube.