CVE-2020-24137: Wcms

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path parameter to wex/cssjs.php.

Affected products

  • Wcms Wcms: version 0.3.2 only

Published 2021-04-07. Last modified 2026-06-17.