Описание
Alist vulnerable to Path Traversal
In versions of Alist prior to 3.6.0, a user with only file upload permission can bypass the base path restriction by using '... /' to bypass the base path restriction and upload files to an arbitrary path.
Пакеты
Наименование
github.com/alist-org/alist/v3
go
Затронутые версииВерсия исправления
< 3.6.0
3.6.0