Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244 - Vulnerability Database
Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2020-21244
Medium
Reference:
CVE-2020-21244
Title:
Frontaccounting Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.