High severity8.1NVD Advisory· Published Mar 25, 2022· Updated Jun 17, 2026
CVE-2020-21554
CVE-2020-21554
Description
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
Affected products
3- TinyShop/TinyShopdescription
Patches
Vulnerability mechanics
References
4- imgur.com/dg1DM5TnvdExploitThird Party Advisory
- imgur.com/pA8OWxanvdExploitThird Party Advisory
- tinyrise.comnvdBroken Link
- tinyrise.com/down.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.