CVE-2020-7882: high-severity vulnerability in Hancomwith anySign4PC
anySign directory traversal vulnerability
Published · Updated
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 7.5epss 1.3%
from disclosure to weapon
Published on NVDNov 22
VulnCheck+1435d
exploitation probability
1.3%top 30% of all CVEs
observed exploitation
yesVulnCheck
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Hancomwith · anySign4PC