PT-2018-16864 · Unknown · Photos In Wifi
Benjamin Kunz Mejri
·
Published
2018-01-08
·
Updated
2018-01-29
·
CVE-2018-5283
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Photos in Wifi application version 1.0.1
Description
The issue concerns directory traversal in the Photos in Wifi application. It is possible to exploit this via the
ext parameter to access files outside the intended directory, specifically through the assets-library://asset/asset.php endpoint.Recommendations
For version 1.0.1, avoid using the
ext parameter in the affected endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the assets-library://asset/asset.php endpoint to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photos In Wifi