Логотип exploitDog
bind:CVE-2024-55658
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55658

Количество 2

Количество 2

nvd логотип

CVE-2024-55658

около 1 года назад

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w9-wqfq-gwqx

около 1 года назад

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-25w9-wqfq-gwqx

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
1%
Низкий
около 1 года назад

Уязвимостей на страницу