Description
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33046 | BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution. |
References
| Link | Providers |
|---|---|
| https://github.com/Exopteron/BiblioRCE |
|
History
Tue, 11 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-11T19:31:53.855Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29478
Updated: 2024-08-02T14:07:46.422Z
Status : Modified
Published: 2023-04-07T04:15:41.360
Modified: 2025-02-11T20:15:32.753
Link: CVE-2023-29478
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD