PT-2017-10928 · I · I
Published
2017-11-17
·
Updated
2017-11-29
·
CVE-2017-1000234
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
I, Librarian versions prior to 4.8
Description
The issue allows an attacker to enumerate directories by navigating through the
dir parameter in the jqueryFileTree.php. This enables the attacker to list directories, potentially revealing sensitive information.Recommendations
For versions prior to 4.8, consider restricting access to the jqueryFileTree.php file or avoiding the use of the
dir parameter in the affected API endpoint until a fix is available.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
I