VYPR
Critical severity9.8NVD Advisory· Published Aug 31, 2020· Updated Jun 17, 2026

CVE-2020-7521

CVE-2020-7521

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of FileUploadServlet which may lead to uploading executable files to non-specified directories.

Affected products

2
  • cpe:2.3:o:schneider-electric:apc_easy_ups_online_software:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:schneider-electric:apc_easy_ups_online_software:*:*:*:*:*:*:*:*range: <=2.0
    • (no CPE)range: <=V2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.