PT-2023-28746 · Unknown · Gladys Assistant

·

CVE-2023-43256

·

Published

2023-09-25

·

Updated

2023-12-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gladys Assistant versions 4.26.1 and below
Description A path traversal issue allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
Recommendations For versions 4.26.1 and below, update to a version above 4.26.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files on the host machine until a patch is available. Avoid using non-sanitized user input in the affected functionality until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-43256

Affected Products

Gladys Assistant