ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37077”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37077
Published
2026-02-03
CVSS:
6.9
ShadowTrackr CVSS:
4.6
Summary:
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.