VULNERABILITY INTELLIGENCE
CVE-2017-20105
CVSS score5.4 MEDIUM
EPSS probability1.03%
CISA KEVNot currently listed
Published2022-06-28
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.8.3 is able to address this issue. It is recommended to upgrade the affected component.
Weakness classification
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Primary references
- cna@vuldb.com — Exploit, Mailing List, Third Party Advisory
- cna@vuldb.com — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory