PT-2026-47202 · Unknown · Hsweb-Framework
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
hs-web hsweb-framework versions prior to 5.0.2
Description
A path traversal issue exists in the File Upload component. The
denied() function within the FileUploadProperties.java file can be manipulated via the filename argument, allowing a remote attacker to access or traverse directories outside the intended folder.Recommendations
Install the patch with identifier 8009845b577d8a2c4bbf4fdd8e8913799a714be6.
As a temporary mitigation, restrict the use of the
filename argument in the File Upload component.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hsweb-Framework