Vulnerability Description
Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execute arbitrary code or obtain sensitive information via unspecified vectors.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Onethird | Onethird | <= 1.96c |
References
- https://jvn.jp/en/vu/JVNVU99467898/index.htmlPatchThird Party Advisory
- https://onethird.net/en/p1340.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU99467898/index.htmlPatchThird Party Advisory
- https://onethird.net/en/p1340.htmlVendor Advisory
FAQ
What is CVE-2020-5640?
CVE-2020-5640 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execute arbitrary code or obtain sensitive information via unspecified vectors.
How severe is CVE-2020-5640?
CVE-2020-5640 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-5640?
Check the references section above for vendor advisories and patch information. Affected products include: Onethird Onethird.