PT-2017-10928 · I · I
Publicado
2017-11-17
·
Atualizado
2017-11-29
·
CVE-2017-1000234
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
I, Librarian versions prior to 4.8
Description
The issue allows an attacker to enumerate directories by navigating through the
dir parameter in the jqueryFileTree.php. This enables the attacker to list directories, potentially revealing sensitive information.Recommendations
For versions prior to 4.8, consider restricting access to the jqueryFileTree.php file or avoiding the use of the
dir parameter in the affected API endpoint until a fix is available.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
I