Impact
A path traversal vulnerability exists in the DefGenProjectController.java component of Dromara lamp-cloud. This flaw is classified as CWE-22, a weakness that allows an attacker to traverse directories. By manipulating the outputDir/parent/projectPrefix request parameters, an attacker can influence the file system path resolution, potentially accessing or writing files outside the intended workspace. The CVE report explicitly states that an attacker can launch this attack remotely and that the exploit has been disclosed to the public.
Affected Systems
The flaw affects Dromara lamp-cloud software up to and including version 5.10.0. No other versions or distinct products are listed as affected within the CNA data. The vendor has not yet released a fix, and the issue remains unaddressed in the repository.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity. With no EPSS score available, the exact exploitation probability is uncertain, yet the ability to trigger the flaw remotely over HTTP makes the vulnerability a security concern for installations exposed to the internet. Although the description does not guarantee arbitrary file read or write, the traversal can lead to unauthorized file access, which can facilitate subsequent compromise. The risk remains elevated until a patch or mitigation is applied.
OpenCVE Enrichment