356
VMScore

CVE-2019-20354

Published: 06/01/2020 Updated: 14/01/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The web application component of piSignage prior to 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pisignage pisignage

Exploits

piSignage version 264 suffers from a directory traversal vulnerability ...