High severity7.5NVD Advisory· Published Nov 22, 2021· Updated Jun 17, 2026
CVE-2020-7882
CVE-2020-7882
Description
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Affected products
4cpe:2.3:a:hancom:anysign4pc:1.1.1.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:hancom:anysign4pc:1.1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:hancom:anysign4pc:1.1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:hancom:anysign4pc:1.1.2.7:*:*:*:*:*:*:*
- Range: 1.1.1.0
Patches
Vulnerability mechanics
References
1- www.boho.or.kr/krcert/secNoticeView.donvdThird Party Advisory
News mentions
1- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without PromptsThe Hacker News · Jul 30, 2026