PT-2022-24888 · Unknown · Gin-Vue-Admin

Eggdkk

+1

·

Published

2022-10-24

·

Updated

2022-10-24

·

CVE-2022-39305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gin-vue-admin versions prior to 2.5.4
Description The issue concerns an arbitrary file read due to insufficient validation of the fileMd5 and fileName parameters in the file upload functionality. This allows unauthorized access to files. The problem is resolved in version 2.5.4b.
Recommendations For versions prior to 2.5.4, update to version 2.5.4b to resolve the issue. As a temporary workaround, consider disabling the file upload feature until the update is applied. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-39305
GHSA-WRMQ-4V4C-GXP2

Affected Products

Gin-Vue-Admin