Логотип exploitDog
bind:CVE-2024-55658
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55658

Количество 2

Количество 2

nvd логотип

CVE-2024-55658

11 месяцев назад

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w9-wqfq-gwqx

11 месяцев назад

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-25w9-wqfq-gwqx

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу