PT-2026-51524 · Pwnlift · Pwnlift
CVSS v3.1
7.4
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pwnlift versions prior to d7a9544
Description
In a privileged deployment, the upload handler in 'Components/Pages/Home.razor' contains a symlink following issue. This occurs when the application follows symbolic links (files that point to another file or directory) during the upload process, which can lead to unauthorized file access or modification.
Recommendations
Update to version d7a9544 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pwnlift