DxRvs/vaultize_CVE-2024-36079

DxRvs/vaultize_CVE-2024-36079

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, a temporary file will be created outside the specified directory when the file is downloaded. To exploit this, an authenticated user would upload a file with an incorrect file name, and then download it.