PT-2023-20730 · Syncfusion · Syncfusion Ej2 Node File Provider
Published
2023-07-12
·
Updated
2023-07-26
·
CVE-2023-26563
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Syncfusion EJ2 Node File Provider version 0102271
Description
The issue allows an unauthenticated attacker to perform various malicious actions due to a directory traversal vulnerability in the filesystem-server.js component. On Windows, this includes listing files in any directory, reading any file, deleting any file, and uploading any file to any directory accessible by the web server. On Linux, an attacker can read any file, download any directory, delete any file, and upload any file to any directory accessible by the web server.
Recommendations
As a temporary workaround, consider disabling the filesystem-server.js component until a patch is available.
Restrict access to the vulnerable filesystem-server.js module to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syncfusion Ej2 Node File Provider