ZeroHour

CVE-2023-29478

PoC
CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

Vendors
bibliocraftmod
Products
bibliocraft
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.