The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2025-06-17T20:59:13.141Z
Reserved: 2023-11-13T13:44:23.702Z
Link: CVE-2023-48249

Updated: 2024-08-02T21:23:39.080Z

Status : Modified
Published: 2024-01-10T11:15:10.090
Modified: 2024-11-21T08:31:18.600
Link: CVE-2023-48249

No data.

No data.