Back to Database
Status published
High
CVE-2020-27180
konzept-ix publiXone before 2020.015 allows attackers to download files by...
Vulnerability Description
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-27180
Credits & Attribution
No credits recorded in the NVD database.
References
More from konzept-ix
View All →CVE-2020-27183
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone...
Critical
9.8
CVE-2020-27182
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015...
Medium
6.1
CVE-2020-27181
A hardcoded AES key in CipherUtils.java in the Java applet...
Medium
6.5
CVE-2020-27179
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary...
Critical
9.8
Affected Vendor
konzept-ix
View all reports →Affected Software
publixone
Vulnerable Versions:
0
Timeline
Official Publish:
October 27th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.