CVE-2020-23766

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
5.5
MEDIUM
Affected
1
PROJECT

Description

An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.

Simple and fast databaseless PHP blogging platform, and Flat-File CMS
GitHubGitHub
1.34K