CVE-2020-37080
CRITICALwebTareas 2.0.p8 - Privilege Escalation
Title source: llmDescription
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through an unauthenticated file deletion mechanism.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
17.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-73
Status
draft
Timeline
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026