CVE-2018-11248

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/05/2018
Last modified:
20/06/2018

Description

util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:liulishuo:filedownloader:1.7.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools