Vulnerability Details CVE-2020-21554
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.3%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.5
Products affected by CVE-2020-21554
-
cpe:2.3:a:tinyrise:tinyshop:3.1.1