Skip to content

Directory Traversal Vulnerability

Critical
iamareebjamal published GHSA-wcm4-2jp5-q269 Oct 15, 2020

Package

No package listed

Affected versions

<=d27ed0f

Patched versions

>=444ae8d

Description

Impact

Insufficient input validation allowed an directory traversal vulnerability. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files can also be moved or deleted

Patches

Patched version:
444ae8d

References

https://en.wikipedia.org/wiki/Directory_traversal_attack

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2020-4039

Weaknesses

No CWEs

Credits