Описание
A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used.
Ссылки
- Exploit
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 0.55.6 (включая)
cpe:2.3:a:upsonic:upsonic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 5.5
github
8 месяцев назад
Upsonic is vulnerable to Path Traversal attack through its os.path.join function
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22