Home
HIGH: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NDefault status
unaffected
3 (semver) before 5.4.12
affected
5.5 (semver) before 5.5.4
affected
5.6 (semver) before 5.6.3
affected
Description
A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, in the context of the application server, from the Linux server.
Problem types
CWE-20 Improper Input Validation
Product status
3 (semver) before 5.4.12
5.5 (semver) before 5.5.4
5.6 (semver) before 5.6.3
Timeline
| 2025-03-04: | Vendor was contacted and informed about the vulnerability via email. |
| 2025-03-04: | Initial response received from vendor. Vendor acknowledged the vulnerability. |
| 2025-03-12: | Vendor informed us that the issue was resolved. |
Credits
Felix Schmid <felix.schmid@cirosec.de>