CVE-2024-6433
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
10/07/2024
Last modified:
12/07/2024
Description
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request to the application with a malicious snapshot_path parameter.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



