CVE-2020-21055
Dashboard / Vulnerabilities / CVE-2020-21055
CVE-2020-21055
Published: 20 May 2021Last Modified: 8 Jul 2026
Summary:
Details: A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
References: https://resp3ctblog.wordpress.com/2019/10/28/fusionpbx-path-traversal-6/, https://github.com/fusionpbx/fusionpbx/commit/1a88ca61a744914d3336cc15a40fb3edbcde9085
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
