Description
LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadImg, oldpic, or imgurl parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20792 | LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadImg, oldpic, or imgurl parameter. |
References
| Link | Providers |
|---|---|
| https://github.com/bettershop/LaikeTui/issues/9 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:05:52.110Z
Reserved: 2021-06-07T00:00:00.000Z
Link: CVE-2021-34129
No data.
Status : Modified
Published: 2021-06-15T20:15:14.147
Modified: 2024-11-21T06:09:56.237
Link: CVE-2021-34129
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD