Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
References
Link | Resource |
---|---|
https://github.com/casdoor/casdoor/issues/1171 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Information
Published : 2022-12-06 18:15
Updated : 2022-12-08 07:27
NVD link : CVE-2022-44942
Mitre link : CVE-2022-44942
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
casbin
- casdoor