CVE-2020-29134

HIGH

Totvs Fluig - Path Traversal

Title source: rule

Description

The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

Exploits (4)

nomisec WORKING POC 3 stars
by Ls4ss · poc
https://github.com/Ls4ss/CVE-2020-29134
inthewild WORKING POC
poc
https://github.com/lsass-exe/cve-2020-29134
inthewild WORKING POC
poc
https://github.com/lucxssouza/cve-2020-29134
exploitdb WORKING POC
by Lucas Souza · bashwebappsmultiple
https://www.exploit-db.com/exploits/49622

Scores

CVSS v3 8.6
EPSS 0.2033
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-22
Status published

Affected Products (3)

totvs/fluig
totvs/fluig
totvs/fluig

Timeline

Published Mar 05, 2021
Tracked Since Feb 18, 2026