CVE-2020-7998
Summary
| CVE | CVE-2020-7998 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-28 05:15:00 UTC |
| Updated | 2020-02-04 15:25:00 UTC |
| Description | An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Super File Explorer Project | Super File Explorer | 1.0.1 | All | All | All |
| Application | Super File Explorer Project | Super File Explorer | 1.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-7998 arbitrary file upload web vulnerability Super File Explorer app for iOS · GitHub | MISC | gist.github.com | Third Party Advisory |
| Super File Explorer - File Viewer & File Manager on the App Store | MISC | apps.apple.com | Product, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.