CVE-2020-21554

A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
References
Link Resource
http://tinyrise.com/ Broken Link
http://tinyrise.com/down.html Broken Link
https://imgur.com/dg1DM5T Exploit Third Party Advisory
https://imgur.com/pA8OWxa Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tinyrise:tinyshop:3.1.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-03-25 16:15

Updated : 2024-02-28 19:09


NVD link : CVE-2020-21554

Mitre link : CVE-2020-21554

CVE.ORG link : CVE-2020-21554


JSON object : View

Products Affected

tinyrise

  • tinyshop