Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244 - Vulnerability Database
            
		
	
    
                    Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244
            
    
        
								Medium
					
					        
        
            Reference:
            
                                CVE-2020-21244
            
        
                    
        
        
            Title:
            Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
        
        
            Overview:
            An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.