HIGH

CVE-2020-35580

CVSS v3

7.5

HIGH

EPSS Score

80.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

Technical details

Published
5/20/2021

Frequently asked questions

What is CVE-2020-35580?

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

Is CVE-2020-35580 actively exploited?

Active exploitation of CVE-2020-35580 has not been confirmed. The EPSS score is 80.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-35580?

CVE-2020-35580 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2020-35580 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.