PT-2018-14460 · Linlinjava · Litemall
Published
2018-10-17
·
Updated
2018-11-29
·
CVE-2018-18434
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
litemall version 0.9.0
Description
An issue in the litemall-wx-api component allows for arbitrary file download via directory traversal. This is possible due to the ../ directory traversal vulnerability in the WxStorageController.java file.
Recommendations
For litemall version 0.9.0, consider restricting access to the WxStorageController.java file or the affected API endpoint until a patch is available. As a temporary workaround, review and limit the usage of directory traversal in the linlinjava/litemall/wx/web/WxStorageController.java file to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litemall