Description
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wv28-7fpw-fj49 | Lektor does not sanitize database path traversal |
References
History
Tue, 06 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:08:26.792Z
Reserved: 2024-03-08T00:00:00.000Z
Link: CVE-2024-28335
Updated: 2024-08-02T00:48:49.674Z
Status : Deferred
Published: 2024-03-27T06:15:19.447
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-28335
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Github GHSA