No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 20 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soniccloudorg
Soniccloudorg sonic-server |
|
| Vendors & Products |
Soniccloudorg
Soniccloudorg sonic-server |
Mon, 20 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-20T15:35:54.833Z
Reserved: 2026-04-19T16:21:58.957Z
Link: CVE-2026-6620
Updated: 2026-04-20T15:35:46.241Z
Status : Received
Published: 2026-04-20T09:16:09.990
Modified: 2026-04-20T09:16:09.990
Link: CVE-2026-6620
No data.
OpenCVE Enrichment
Updated: 2026-04-20T14:58:00Z