PT-2023-28746 · Unknown · Gladys Assistant
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gladys Assistant versions 4.26.1 and below
Description
A path traversal issue allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
Recommendations
For versions 4.26.1 and below, update to a version above 4.26.1 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive files on the host machine until a patch is available.
Avoid using non-sanitized user input in the affected functionality until the issue is resolved.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gladys Assistant