CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It may be remotely exploitable.
CVE
CVE-2020-36240
Severity
MEDIUM
CVSS
5.3
EPSS
1.23%
Original NVD Description
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Related CVEs
Other vulnerabilities affecting the same vendor(s)