CVE-2020-7882

HIGH EXPLOITED

Hancom AnySign4PC - Path Traversal and Arbitrary File Deletion via getPFXFolderList Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-7882 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0121
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-10-27
CWE
CWE-22 CWE-24
Status published
Products (3)
hancom/anysign4pc 1.1.1.0
hancom/anysign4pc 1.1.2.6
hancom/anysign4pc 1.1.2.7
Published Nov 22, 2021
Tracked Since Feb 18, 2026