Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-39942

6 месяцев назад

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as uploaded_by to obscure the tampering. This vulnerability is fixed in 11.17.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-393c-p46r-7c95

6 месяцев назад

Directus: Path Traversal and Broken Access Control in File Management API

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-39942

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as uploaded_by to obscure the tampering. This vulnerability is fixed in 11.17.0.

CVSS3: 8.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-393c-p46r-7c95

Directus: Path Traversal and Broken Access Control in File Management API

CVSS3: 8.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу