CVE-2020-7998 Information
Feb 14, 2021
cve
Description
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default there is no password set for the FTP or Web UI service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://apps.apple.com/us/app/super-file-explorer-file-viewer-file-manager/id1101973946 https://gist.github.com/adeshkolte/9e60b2483d2f20d1951beac0fc917c6f
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: