CVE-2020-7882

HIGH EXPLOITED

Hancom AnySign4PC - Path Traversal

Title source: llm
STIX 2.1

Description

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-10-27
CWE
CWE-22 CWE-24
Status published
Products (3)
hancom/anysign4pc 1.1.1.0
hancom/anysign4pc 1.1.2.6
hancom/anysign4pc 1.1.2.7
Published Nov 22, 2021
Tracked Since Feb 18, 2026