ZeroHour

CVE-2022-23082

CVSS 3.1
7.5 high
EPSS
1%p70
Published
()
Modified
Description

In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

Vendors
mend
Products
curekit
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.