CVE-2023-47440

G

ladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.

Configurations

Configuration 1 (hide)

cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:30

Type Values Removed Values Added
References () https://blog.moku.fr/cve/ - Third Party Advisory () https://blog.moku.fr/cve/ - Third Party Advisory
References () https://blog.moku.fr/cves/CVE-2023-47440/ - Third Party Advisory () https://blog.moku.fr/cves/CVE-2023-47440/ - Third Party Advisory
References () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - Patch () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - Patch

Information

Published : 2023-12-07 18:15

Updated : 2024-11-21 08:30


NVD link : CVE-2023-47440

Mitre link : CVE-2023-47440

CVE.ORG link : CVE-2023-47440


JSON object : View

Products Affected
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')