8.8
CVSSv3

CVE-2020-7998

Published: 28/01/2020 Updated: 04/02/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

super file explorer project super file explorer 1.0.1

Github Repositories

My-CVEs List of my CVE published CVE-2020-7997 : ASUS WRT-AC66U 3 RT 3004372_67 devices allow XSS via the Client Name field to the Parental Control feature nvdnistgov/vuln/detail/CVE-2020-7997 CVE-2020-7998 : An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 101 for iOS The vulnerability is located in the developer path