CVE-2020-36825 describes a critical unrestricted upload vulnerability in the download_file function of Server/api.php within cyberaz0r WebRAT, affecting versions up to 20191222. The vulnerability allows remote attackers to upload arbitrary files by manipulating the 'name' argument. While initially classified as critical, its existence is disputed, and it affects an unsupported product with minimal usage. The CVSS score of 6.3 (Medium) indicates a network-based attack with low complexity and privileges, potentially leading to low impact on confidentiality, integrity, and availability. However, the EPSS score is extremely low, suggesting a very low probability of exploitation in the wild. There is no evidence of active exploitation, exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The CVE itself is controversial, with the project maintainer arguing against its eligibility due to its age, resolution, and the product's obscurity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cyberaz0r | WebRAT | 20191222CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.