PT-2024-36572 · Siyuan · Siyuan
Elleuch-X1
·
Published
2024-12-11
·
Updated
2024-12-18
·
CVE-2024-55658
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.1.16
Description
SiYuan is a personal knowledge management system. The /api/export/exportResources endpoint is vulnerable to arbitrary file read via path traversal. It is possible to manipulate the
paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure.Recommendations
For versions prior to 3.1.16, update to version 3.1.16 to resolve the issue. As a temporary workaround, consider restricting access to the /api/export/exportResources endpoint until the update is applied. Avoid using the
paths parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan