Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jpg-2rj5-964c

Опубликовано: 17 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 5.3

Описание

lsFusion Platform has a Path Traversal vulnerability

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Пакеты

Наименование

lsfusion.platform:web-client

maven
Затронутые версииВерсия исправления

<= 6.1

Отсутствует

EPSS

Процентиль: 50%
0.00268
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

EPSS

Процентиль: 50%
0.00268
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-22