CVE-2018-20094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
12/12/2018
Last modified:
04/01/2019

Description

An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xuxueli:xxl-conf:1.6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools