Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
References
Link | Resource |
---|---|
https://github.com/lmy1342554547/p2pProject/issues/1 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-03-03 20:29
Updated : 2021-07-21 04:39
NVD link : CVE-2019-9552
Mitre link : CVE-2019-9552
JSON object : View
CWE
CWE-425
Direct Request ('Forced Browsing')
Products Affected
eloan_project
- eloan