Record summary

CVE-2020-35736 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHGateOne 1.1 - Local File InclusionCVSS 7.5

GateOne 1.1 allows arbitrary file retrieval without authentication via /downloads/.. local file inclusion because os.path.join is incorrectly used.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the affected system.

Remediation

Apply the latest security patches or updates provided by the vendor to mitigate the LFI vulnerability in GateOne 1.1.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2020gateonelfiliftoffsoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:liftoffsoftware:gateone:1.1:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3