A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function…
VulDB·CWE-24·Published 2024-03-17
In PandaXGO PandaX bis 20240310 wurde eine kritische Schwachstelle gefunden. Betroffen ist die Funktion DeleteImage der Datei /apps/system/router/upload.go. Durch die Manipulation des Arguments fileName mit der Eingabe ../../../../../../../../../tmp/1.txt mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.
A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../../../../../../../tmp/1.txt leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257062 is the identifier assigned to this vulnerability.
A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../../../../../../../tmp/1.txt leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257062 is the identifier assigned to this vulnerability.
Una vulnerabilidad ha sido encontrada en PandaXGO PandaX hasta 20240310 y clasificada como crítica. Esta vulnerabilidad afecta a la función DeleteImage del archivo /apps/system/router/upload.go. La manipulación del argumento fileName con la entrada ../../../../../../../../../tmp/1.txt conduce al path traversal: '../ archivodir'. El ataque se puede iniciar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-257062 es el identificador asignado a esta vulnerabilidad.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | cve.org | 5.5 | — | — | AV:N/AC:L/Au:S/C:N/I:P/A:P |
| 2.0 | Primary | cve.org | 5.5 | — | — | AV:N/AC:L/Au:S/C:N/I:P/A:P |
| 2.0 | Secondary | NVD | 5.5 | 8.0 | 4.9 | AV:N/AC:L/Au:S/C:N/I:P/A:P |
| 3.0 | Primary | cve.org | 5.4 | — | — | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.0 | Primary | cve.org | 5.4 | — | — | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | NVD | 9.8 | 3.9 | 5.9 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | Primary | cve.org | 5.4 | — | — | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | cve.org | 5.4 | — | — | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Secondary | NVD | 5.4 | 2.8 | 2.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |