Vulnerability Details CVE-2020-7882
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.4
Products affected by CVE-2020-7882
-
cpe:2.3:a:hancom:anysign4pc:1.1.1.0
-
cpe:2.3:a:hancom:anysign4pc:1.1.2.6
-
cpe:2.3:a:hancom:anysign4pc:1.1.2.7
-
cpe:2.3:o:microsoft:windows:-