ZeroHour

CVE-2023-26126

PoC ×2
CVSS 3.1
5.3 medium
EPSS
<1%p61
Published
()
Modified
Description

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

Vendors
m.static project
Products
m.static
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.