Количество 2
Количество 2
CVE-2026-39942
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as uploaded_by to obscure the tampering. This vulnerability is fixed in 11.17.0.
GHSA-393c-p46r-7c95
Directus: Path Traversal and Broken Access Control in File Management API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39942 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as uploaded_by to obscure the tampering. This vulnerability is fixed in 11.17.0. | CVSS3: 8.5 | 0% Низкий | 6 месяцев назад | |
GHSA-393c-p46r-7c95 Directus: Path Traversal and Broken Access Control in File Management API | CVSS3: 8.5 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу