Back to overview

CVE-2020-37080

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through an unauthenticated file deletion mechanism.

Metadata

CVE ID
CVE-2020-37080
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-02-01 13:16 UTC
Published
2026-02-03 22:01 UTC
Last updated
2026-03-05 01:27 UTC
Primary CWE
CWE-73
External Control of File Name or Path
Vendor / Product
luiswang / webTareas
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
luiswang webTareas 2.0.p8
Weakness (CWE)
CWESourceDescription
CWE-73 cna External Control of File Name or Path
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.2 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
References (3)
Back to overview