← Vulnerability feed

Vulnerability record · CVE-2020-36882 · published 5 December 2025

CVE-2020-36882: Flexense diskboss unrestricted file upload vulnerability

Flexense · Diskboss

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.

8.7 CVSS 4.0 High EPSS 0.62% · top 52.5% CWE-434 · Unrestricted file upload
8.7CVSS 4.0 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-36882 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5262Flexense diskboss out-of-bounds write vulnerabilityA stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the contex…EPSS 39%8.6CVE-2020-36881Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to …EPSS 0.37%8.6CVE-2020-36880Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute…EPSS 0.24%8.1CVE-2018-5261Flexense diskboss missing encryption vulnerabilityAn issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryp…EPSS 0.46%7.8CVE-2017-7310Flexense disk tools XML import buffer overflow allows code executionA buffer overflow in the Import Command of multiple Flexense products (SyncBreeze, DiskSorter, DiskBoss, DiskPulse, DiskSavvy, DupScout, VX Search) b…EPSS 54%analysed7.5CVE-2017-15665Flexense diskboss vulnerabilityIn Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GE…EPSS 9.1%6.1CVE-2018-10294Flexense diskboss cross-site scripting vulnerabilityFlexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.EPSS 0.69%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2020-36882), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.