CVE-2020-29071

CRITICALCVSS 9/10EPSS 1.64%

Last modified

CVE-2020-29071 is a critical-severity vulnerability rated 9/10 on the CVSS scale. An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. EPSS estimates a 1.64% chance of exploitation in the next 30 days.

Description

An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.

Metrics

CVSS 3.1
9/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS Probability
1.64%

73.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LiquidfilesLiquidfiles< 3.3.19

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-29071?
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.
How severe is CVE-2020-29071?
CVE-2020-29071 has a CVSS score of 9/10 (CRITICAL severity). The EPSS model estimates a 1.64% probability of exploitation in the next 30 days.
How do I fix CVE-2020-29071?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-29071?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST