Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244 - Vulnerability Database

Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244

Medium
Reference: CVE-2020-21244
Title: Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.