CVE-2021-26629

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/04/2022
Last modified:
06/05/2022

Description

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tobesoft:xplatform:*:*:*:*:*:*:*:* 9.2.2.284 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*