vendor:
Jreport
by:
hongphukt
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Jreport
Affected Version From: JReport 15.6
Affected Version To: JReport 15.6
Patch Exists: NO
Related CWE: N/A
CPE: a:jinfonet:jreport:15.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux, Windows
2020
Jinfornet Jreport 15.6 – Unauthenticated Directory Traversal
Jreport Help function have a path traversal vulnerability in the SendFileServlet allows remote unauthenticated users to view any files on the Operating System with Application services user permission. This vulnerability affects Windows and Unix operating systems.
Mitigation:
Ensure that the application is not vulnerable to directory traversal attacks by validating user input and restricting access to sensitive files.