PoC Index

CVE-2020-23172

MEDIUM 5.5EPSS 0.7%

A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.

CVSS v3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
0.74% chance of exploitation in the next 30 days, 52th percentile
Published
2021-08-10
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related