Improper Preservation of Permissions
CVE-2020-36070
Summary
Insecure Permission vulnerability found in tcg/voyager allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-281 - Improper Preservation of Permissions
The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
References
Advisory Timeline
- Published