CVE-2020-24137

MEDIUM

wcms 0.3.2 - Path Traversal via wex/cssjs.php Path Parameter

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path parameter to wex/cssjs.php.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/vedees/wcms/issues/7

Scores

CVSS v3 5.3
EPSS 0.0141
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
wcms/wcms 0.3.2
Published Apr 07, 2021
Tracked Since Feb 18, 2026