Vulnerabilities > CVE-2020-20948 - Exposure of Resource to Wrong Sphere vulnerability in Jeecg 3.8

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
jeecg
CWE-668

Summary

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

Vulnerable Configurations

Part Description Count
Application
Jeecg
1

Common Weakness Enumeration (CWE)