CVE-2020-21554

A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
References
Link Resource
http://tinyrise.com/ Broken Link
http://tinyrise.com/down.html Broken Link
https://imgur.com/dg1DM5T Exploit Third Party Advisory
https://imgur.com/pA8OWxa Exploit Third Party Advisory
http://tinyrise.com/ Broken Link
http://tinyrise.com/down.html Broken Link
https://imgur.com/dg1DM5T Exploit Third Party Advisory
https://imgur.com/pA8OWxa Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tinyrise:tinyshop:3.1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 05:12

Type Values Removed Values Added
References () http://tinyrise.com/ - Broken Link () http://tinyrise.com/ - Broken Link
References () http://tinyrise.com/down.html - Broken Link () http://tinyrise.com/down.html - Broken Link
References () https://imgur.com/dg1DM5T - Exploit, Third Party Advisory () https://imgur.com/dg1DM5T - Exploit, Third Party Advisory
References () https://imgur.com/pA8OWxa - Exploit, Third Party Advisory () https://imgur.com/pA8OWxa - Exploit, Third Party Advisory

31 Mar 2022, 16:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.5
v3 : 8.1
CWE NVD-CWE-noinfo
References (MISC) https://imgur.com/dg1DM5T - (MISC) https://imgur.com/dg1DM5T - Exploit, Third Party Advisory
References (MISC) http://tinyrise.com/ - (MISC) http://tinyrise.com/ - Broken Link
References (MISC) http://tinyrise.com/down.html - (MISC) http://tinyrise.com/down.html - Broken Link
References (MISC) https://imgur.com/pA8OWxa - (MISC) https://imgur.com/pA8OWxa - Exploit, Third Party Advisory
CPE cpe:2.3:a:tinyrise:tinyshop:3.1.1:*:*:*:*:*:*:*

25 Mar 2022, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-25 16:15

Updated : 2024-11-21 05:12


NVD link : CVE-2020-21554

Mitre link : CVE-2020-21554

CVE.ORG link : CVE-2020-21554


JSON object : View

Products Affected

tinyrise

  • tinyshop