PT-2019-19821 · Logicaldoc · Logicaldoc Community Edition
Publicado
2019-05-30
·
Atualizado
2019-06-11
·
CVE-2019-9723
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LogicalDOC Community Edition versions 8.0 through 8.2.0
Description
The issue allows for path traversal, enabling the reading of arbitrary files and the creation of directories. This is due to a vulnerability in the PluginRegistry class.
Recommendations
For versions 8.0 through 8.2.0, update to version 8.2.1 to resolve the issue.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Logicaldoc Community Edition