CVE-2024-0341

A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manipulation of the argument path leads to path traversal: ‘../filedir’. The exploit has been disclosed to the public and may be used. The identifier VDB-250109 was assigned to this vulnerability.

More information : https://note.zhaoj.in/share/VYx8H9u8gyHw

Attack vector : NETWORK
Attack complexity : LOW
Privileges required : NONE
User interaction : NONE
Confidentiality impact : HIGH
Integrity impact : NONE
Base score : 7.5
Base severity : HIGH
Exploitability score : 3.9
Impact score : 3.6