PT-2023-20731 · Syncfusion · Syncfusion Ej2 Aspcore File Provider
Published
2023-07-12
·
Updated
2023-07-26
·
CVE-2023-26564
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Syncfusion EJ2 ASPCore File Provider version 3ac357f
Description
The issue allows an unauthenticated attacker to perform directory traversal via Models/PhysicalFileProvider.cs. This enables the attacker to list files within a directory, download any file, or upload any file to any directory accessible by the web server.
Recommendations
For Syncfusion EJ2 ASPCore File Provider version 3ac357f, consider restricting access to the Models/PhysicalFileProvider.cs file as a temporary workaround until a patch is available. Additionally, restrict upload and download capabilities to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syncfusion Ej2 Aspcore File Provider