Логотип exploitDog
bind:CVE-2024-55658
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55658

Количество 2

Количество 2

nvd логотип

CVE-2024-55658

больше 1 года назад

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w9-wqfq-gwqx

больше 1 года назад

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-25w9-wqfq-gwqx

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу