CVE-2020-7882
HIGH EXPLOITEDHancom AnySign4PC - Path Traversal and Arbitrary File Deletion via getPFXFolderList Parameter
Title source: llmExploitation Summary
CVE-2020-7882 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36344
Scores
CVSS v3
7.5
EPSS
0.0121
EPSS Percentile
64.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2025-10-27
CWE
CWE-22
CWE-24
Status
published
Products (3)
hancom/anysign4pc
1.1.1.0
hancom/anysign4pc
1.1.2.6
hancom/anysign4pc
1.1.2.7
Published
Nov 22, 2021
Tracked Since
Feb 18, 2026