PT-2024-26285 · Svnwebui · Svnwebui

Niiiiko

·

Published

2024-05-24

·

Updated

2024-07-03

·

CVE-2024-34995

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions svnWebUI version 1.8.3
Description The issue allows attackers to delete arbitrary files by sending a crafted POST request. This is achieved via the dirTemps parameter under the com.cym.controller.UserController#importOver function.
Recommendations For svnWebUI version 1.8.3, consider restricting access to the com.cym.controller.UserController#importOver function until a patch is available. As a temporary workaround, avoid using the dirTemps parameter in the affected API endpoint to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-34995

Affected Products

Svnwebui