Описание
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
EPSS
Процентиль: 19%
0.00266
Низкий
8.7 High
CVSS3
Дефекты
CWE-73
Связанные уязвимости
CVSS3: 8.7
github
15 дней назад
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
EPSS
Процентиль: 19%
0.00266
Низкий
8.7 High
CVSS3
Дефекты
CWE-73