PT-2022-17194 · Sprinfall · Webcc
Published
2022-02-18
·
Updated
2022-02-25
·
CVE-2022-25298
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
sprinfall/webcc versions prior to 0.3.0
Description
The issue allows directory traversal, enabling the fetching of arbitrary files from the server. This is a result of a flaw in the package that permits accessing files outside the intended directory structure.
Recommendations
For versions prior to 0.3.0, update to version 0.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories on the server to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webcc