CVE-2020-7998
Last modified
CVE-2020-7998 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Super File Explorer Project | Super File Explorer | 1.0.1 |
References
- https://apps.apple.com/us/app/super-file-explorer-file-viewer-file-manager/id1101973946Product, Third Party Advisory
- https://gist.github.com/adeshkolte/9e60b2483d2f20d1951beac0fc917c6fThird Party Advisory
- https://apps.apple.com/us/app/super-file-explorer-file-viewer-file-manager/id1101973946Product, Third Party Advisory
- https://gist.github.com/adeshkolte/9e60b2483d2f20d1951beac0fc917c6fThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7998?
How severe is CVE-2020-7998?
How do I fix CVE-2020-7998?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7991Adive Framework 2.0.8 has admin/config CSRF to change the Ad…8.8
- CVE-2020-7993Prototype 1.6.0.1 allows remote authenticated users to forge…4.3
- CVE-2020-7994Multiple cross-site scripting (XSS) vulnerabilities in Dolib…6.1
- CVE-2020-7995The htdocs/index.php?mainmenu=home login page in Dolibarr 10…9.8
- CVE-2020-7996htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows …6.1
- CVE-2020-7997ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the…6.1
- CVE-2020-7999The Intellian Aptus application 1.0.2 for Android has hardco…9.8
- CVE-2020-8000Intellian Aptus Web 1.24 has a hardcoded password of 1234567…9.8
- CVE-2020-8001The Intellian Aptus application 1.0.2 for Android has a hard…9.8
- CVE-2020-8002A NULL pointer dereference in vrend_renderer.c in virglrende…5.5
- CVE-2020-8003A double-free vulnerability in vrend_renderer.c in virglrend…5.5
- CVE-2020-8004STMicroelectronics STM32F1 devices have Incorrect Access Con…7.5
Are you affected by CVE-2020-7998?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
