Vulnerabilities (CVE)

Filtered by vendor Xmpp-http-upload Project
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15239 1 Xmpp-http-upload Project 1 Xmpp-http-upload 2024-11-21 4.0 MEDIUM 3.5 LOW
In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other limitations on the outbound (GET) traffic. For example, in a scenario where a single server has multiple instances of the application running (with separate DATA_ROOT settings), an ...

Show More