Описание
A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component org.noear.solon.core.handle.RenderManager. The manipulation of the argument template with the input ../org/example/HelloApp.class leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
EPSS
Процентиль: 51%
0.00277
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-23
Связанные уязвимости
EPSS
Процентиль: 51%
0.00277
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-23