PT-2026-84584 · Airasia · Airasia Move App
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
AirAsia MOVE App versions prior to 12.47.2
Description
A path traversal issue exists in the
com.airasia.mobile component. This occurs within the getRealPath() function of com.airasia.core.utils.RealPathUtil when the display name argument is manipulated. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.Recommendations
Update AirAsia MOVE App to version 12.47.2 or later.
As a temporary workaround, restrict the use of the
display name argument within the getRealPath() function.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airasia Move App