Vulnerability Description
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVSS Score
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webtareas Project | Webtareas | <= 2.1 |
Related Weaknesses (CWE)
References
- https://medium.com/%40tehwinsam/webtareas-2-1-c8b406c68c2a
- https://sourceforge.net/p/webtareas/tickets/40/Third Party Advisory
- https://sourceforge.net/projects/webtareas/files/Release NotesThird Party Advisory
- https://medium.com/%40tehwinsam/webtareas-2-1-c8b406c68c2a
- https://sourceforge.net/p/webtareas/tickets/40/Third Party Advisory
- https://sourceforge.net/projects/webtareas/files/Release NotesThird Party Advisory
FAQ
What is CVE-2020-25733?
CVE-2020-25733 is a vulnerability with a CVSS score of 7.5 (HIGH). webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
How severe is CVE-2020-25733?
CVE-2020-25733 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25733?
Check the references section above for vendor advisories and patch information. Affected products include: Webtareas Project Webtareas.