Description
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30359 | The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server. |
References
History
Thu, 07 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-07T15:09:03.521Z
Reserved: 2023-02-26T00:00:00.000Z
Link: CVE-2023-26564
Updated: 2024-08-02T11:53:53.899Z
Status : Modified
Published: 2023-07-12T21:15:09.047
Modified: 2024-11-21T07:51:45.640
Link: CVE-2023-26564
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD