Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-3089

5 месяцев назад

Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.This issue affects prior versions of Actual Sync Server 26.3.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27vg-33gh-4hwg

5 месяцев назад

Actual Sync Server has an Authenticated Path Traversal

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-3089

Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.This issue affects prior versions of Actual Sync Server 26.3.0.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-27vg-33gh-4hwg

Actual Sync Server has an Authenticated Path Traversal

0%
Низкий
5 месяцев назад

Уязвимостей на страницу