PT-2016-4848 · Radicale · Radicale

Unrud

·

Published

2016-02-03

·

Updated

2022-05-17

·

CVE-2016-1505

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Radicale versions prior to 1.1
Description The issue allows remote attackers to read or write to arbitrary files via a crafted path. For example, a crafted path like '/c:/file/ignore' can be used to access files on the system.
Recommendations For versions prior to 1.1, update to version 1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the filesystem storage backend to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1505
GHSA-84CW-MXHV-QVV4

Affected Products

Radicale