PenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.6epss 0.7%
probabilidad de explotación
0.7%top 49% de las CVE
explotación observada
noninguna fuente lo reporta
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 contains a patch for the issue.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Productos afectados
pwndoc · pwndocReferencias
https://gist.github.com/JorianWoltjer/8a42e25c6dfa7604020d2a226e193407https://github.com/pwndoc/pwndoc/blob/2e7f5747d5688b1368e549c786ce7266fe5ab2b5/backend/src/routes/template.js#L103https://github.com/pwndoc/pwndoc/blob/2e7f5747d5688b1368e549c786ce7266fe5ab2b5/backend/src/routes/template.js#L43-L47https://github.com/pwndoc/pwndoc/commit/1d4219c596f4f518798492e48386a20c6e9a2fe6https://github.com/pwndoc/pwndoc/security/advisories/GHSA-2mqc-gg7h-76p6