PT-2026-47202 · Unknown · Hsweb-Framework

·

CVE-2026-11470

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions hs-web hsweb-framework versions prior to 5.0.2
Description A path traversal issue exists in the File Upload component. The denied() function within the FileUploadProperties.java file can be manipulated via the filename argument, allowing a remote attacker to access or traverse directories outside the intended folder.
Recommendations Install the patch with identifier 8009845b577d8a2c4bbf4fdd8e8913799a714be6. As a temporary mitigation, restrict the use of the filename argument in the File Upload component.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11470
GHSA-VJMR-F5FC-VR2W

Affected Products

Hsweb-Framework