CVE-2024-50054
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/11/2024
Last modified:
22/11/2024
Description
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH