PT-2026-103537 · Kiteworks · Kiteworks Core
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiteworks Core versions prior to 9.5.0
Description
An improper restriction of a user-supplied file path in an administrative export feature allows an authenticated administrator to write a file to an arbitrary location on the underlying host. This arbitrary file write could potentially lead to command execution on the appliance. Exploitation requires an authenticated administrative account with access to the affected export function.
Recommendations
Update Kiteworks Core to version 9.5.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiteworks Core