ZeroHour

CVE-2023-1800

PoC
CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224768.

Vendors
go-fastdfs project
Products
go-fastdfs
Weakness
CWE-24, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.