PT-2023-10103 · Unknown · Rails-Cv-App
Published
2023-01-02
·
Updated
2024-05-17
·
CVE-2014-125033
CVSS v2.0
2.7
Low
| Vector | AV:A/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rails-cv-app (affected versions not specified)
Description
A problematic issue has been found, affecting some unknown functionality of the file app/controllers/uploaded files controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal. The issue has been publicly disclosed and may be exploited.
Recommendations
Apply the patch identified as 0d20362af0a5f8a126f67c77833868908484a863 to fix this issue. As a temporary workaround, consider restricting access to the
uploaded files controller to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rails-Cv-App