Описание
Directory Traversal in Gladys Assistant
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
Пакеты
Наименование
gladys
npm
Затронутые версииВерсия исправления
<= 4.27.0
Отсутствует
Связанные уязвимости
CVSS3: 6.5
nvd
около 2 лет назад
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.