An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:58:19.079Z

Reserved: 2018-12-25T00:00:00

Link: CVE-2018-20437

cve-icon Vulnrichment

Updated: 2024-08-05T11:58:19.079Z

cve-icon NVD

Status : Modified

Published: 2018-12-25T15:29:00.240

Modified: 2024-11-21T04:01:28.877

Link: CVE-2018-20437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.