PT-2024-15887 · Qwdigital · Qwdigital Linkwechat
Biantaibao
·
Published
2024-01-25
·
Updated
2024-05-17
·
CVE-2024-0882
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
qwdigital LinkWechat version 5.1.0
Description
A vulnerability was found in qwdigital LinkWechat, affecting an unknown part of the file /linkwechat-api/common/download/resource of the component Universal Download Interface. The manipulation of the
name argument with the input /profile/../../../../../etc/passwd leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations
For qwdigital LinkWechat version 5.1.0, as a temporary workaround, consider restricting access to the
/linkwechat-api/common/download/resource endpoint until a patch is available. Avoid using the name argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qwdigital Linkwechat