The back-end does not sufficiently verify the user...
High severity
Unreviewed
Published
Nov 23, 2024
to the GitHub Advisory Database
•
Updated Nov 23, 2024
Description
Published by the National Vulnerability Database
Nov 22, 2024
Published to the GitHub Advisory Database
Nov 23, 2024
Last updated
Nov 23, 2024
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
References