Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
References
Link Resource
https://github.com/wuzhicms/wuzhicms/issues/191 Exploit Issue Tracking Third Party Advisory
https://www.cnvd.org.cn/flaw/show/2394661 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-12T10:21:39

Updated: 2021-10-12T10:21:39

Reserved: 2020-11-02T00:00:00


Link: CVE-2020-28145

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-12T11:15:07.317

Modified: 2021-10-18T19:54:59.063


Link: CVE-2020-28145

JSON object: View

cve-icon Redhat Information

No data.

CWE