CVE-2020-37080 PUBLISHED

webTareas 2.0.p8 - Arbitrary File Deletion

Assigner: VulnCheck
Reserved: 01.02.2026 Published: 03.02.2026 Updated: 04.02.2026

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through an unauthenticated file deletion mechanism.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor luiswang
Product webTareas
Versions
  • Version 2.0.p8 is affected

Credits

  • Besim ALTINOK finder

References

Problem Types

  • External Control of File Name or Path CWE