← back
CVE-2024-55602highCWE-22

PenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.6epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 contains a patch for the issue.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Affected products
pwndoc · pwndoc