PT-2018-5216 · Unknown · Structured Data Linter
Skyplabs
·
Published
2018-01-02
·
Updated
2018-01-16
·
CVE-2017-1000448
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Structured Data Linter versions 2.4.1 and older
Description
The issue allows for a directory traversal attack through the URL input field, potentially disclosing information about the remote host.
Recommendations
For versions 2.4.1 and older, update to a version newer than 2.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the URL input field to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Structured Data Linter