Booked Scheduler 2.7.7 - Authenticated Directory Traversal
Vulnerability Description
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37077
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Besim ALTINOK
References
More from Twinkle Toes Software
View All →Affected Vendor
Twinkle Toes Software
View all reports →