A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
References
Link | Resource |
---|---|
https://blog.moku.fr/cves/CVE-2023-43256/ | Third Party Advisory |
https://blog.moku.fr/cves/CVE-unassigned/ | Third Party Advisory |
https://github.com/GladysAssistant/Gladys/commit/f27d0ea4689c3deca5739b5f9ed45a2ddbf00b7b | Patch |
Configurations
History
No history.
Information
Published : 2023-09-25 14:15
Updated : 2023-10-13 01:11
NVD link : CVE-2023-43256
Mitre link : CVE-2023-43256
CVE.ORG link : CVE-2023-43256
JSON object : View
Products Affected
gladysassistant
- gladys_assistant
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')