Vulnerability Description
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip and download files even if they do not have permission to view whether the file exists.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cerberusftp | Ftp Server | 8.0 |
Related Weaknesses (CWE)
References
- https://support.cerberusftp.com/hc/en-us/community/topics/360000164199-AnnouncemVendor Advisory
- https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilitiesExploitThird Party Advisory
- https://support.cerberusftp.com/hc/en-us/community/topics/360000164199-AnnouncemVendor Advisory
- https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilitiesExploitThird Party Advisory
FAQ
What is CVE-2020-5194?
CVE-2020-5194 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification oc...
How severe is CVE-2020-5194?
CVE-2020-5194 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5194?
Check the references section above for vendor advisories and patch information. Affected products include: Cerberusftp Ftp Server.