CVE-2020-7998
Last modified
CVE-2020-7998 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Super File Explorer Project | Super File Explorer | 1.0.1 |
References
- https://apps.apple.com/us/app/super-file-explorer-file-viewer-file-manager/id1101973946Product, Third Party Advisory
- https://gist.github.com/adeshkolte/9e60b2483d2f20d1951beac0fc917c6fThird Party Advisory
- https://apps.apple.com/us/app/super-file-explorer-file-viewer-file-manager/id1101973946Product, Third Party Advisory
- https://gist.github.com/adeshkolte/9e60b2483d2f20d1951beac0fc917c6fThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7998?
How severe is CVE-2020-7998?
How do I fix CVE-2020-7998?
Are you affected by CVE-2020-7998?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
