vendor:
SOTEeSKLEP
by:
dun
7.5
CVSS
HIGH
Remote File Disclosure
22
CWE
Product Name: SOTEeSKLEP
Affected Version From: 3.1RC8
Affected Version To: 3.5RC9
Patch Exists: NO
Related CWE:
CPE: sote:esklep
Platforms Tested:
2007
SOTEeSKLEP Remote File Disclosure Vulnerability
The vulnerability allows an attacker to disclose arbitrary files on the remote system. By manipulating the 'file' parameter in the '/go/_files/' directory, an attacker can access files outside of the intended directory. This can lead to the disclosure of sensitive information and potentially compromise the system.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and validate file paths before accessing them. Additionally, restricting access to sensitive files and directories can help prevent unauthorized access.