Vulnerabilities (CVE)

Filtered by vendor Open-mss
Filtered by product Mission Support System
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25123 1 Open-mss 1 Mission Support System 2025-01-09 N/A 7.3 HIGH
MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The `filename` variable is joined with other variables to form a file path in `_file`. However, `filename` is a route parameter that can capture path type values i.e. values including slashes (\). So it is pos ...

Show More