PT-2022-23171 · Unknown · Mangadex-Downloader

Mansuf

·

Published

2022-09-07

·

Updated

2022-09-16

·

CVE-2022-36082

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mangadex-downloader versions 1.3.0 through 1.7.2
Description The issue occurs when using the file:<location> command with a web URL location, causing the mangadex-downloader to attempt to open and read a file on the local disk for each line of website content. This could potentially allow unauthorized access to local files. The app only reads the files without executing them, but it is still a significant concern.
Recommendations For mangadex-downloader versions 1.3.0 through 1.7.1, update to version 1.7.2 or later to resolve the issue. For version 1.7.2, no further action is required as it contains a patch for this issue. As a temporary workaround for versions prior to 1.7.2, consider double-checking the URL before proceeding to download.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-36082
GHSA-R9X7-2XMR-V8FW
PYSEC-2022-264

Affected Products

Mangadex-Downloader