CVE-2020-37278P1HIGHCVSS 7.5Exploitedv*2026-10-02
CVE-2020-37278 [HIGH] CWE-918 CVE-2020-37278: Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote att
Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and
nvd