CVE-2022-35410
PoC ×2—CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.
In the news0 stories
No ingested article mentions this CVE yet.