CVE-2018-11248

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:liulishuo:filedownloader:1.7.3:*:*:*:*:*:*:*n/an/a1.7.3

External Links