Security Advisory

CVE-2020-36970

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-28 17:35:11
Last updated 2026-01-28 21:29:26
Assigner VulnCheck
State PUBLISHED

Description

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the chemin parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.