Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gj5-vjr8-vv8h

Опубликовано: 22 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

EPSS

Процентиль: 66%
0.00515
Низкий

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.

EPSS

Процентиль: 66%
0.00515
Низкий

Дефекты

CWE-552