PT-2024-13803 · Unknown · Lif Auth Server

Superior126

·

Published

2024-01-12

·

Updated

2024-01-22

·

CVE-2023-49801

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lif Auth Server versions prior to 1.4.0
Description The issue relates to the get pfp and get banner routes on Auth Server, where there is no check to ensure that the file received through these URLs is correct. This could allow an attacker access to files they shouldn't have access to.
Recommendations For versions prior to 1.4.0, update to version 1.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the get pfp and get banner routes until the update is applied.

Exploit

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2023-49801
GHSA-3V77-PVQQ-QG3F

Affected Products

Lif Auth Server