This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: WhoDB (v0.45.0-) suffers from **Path Traversal**. ๐ **Consequences**: Unauthenticated attackers can read **any** SQLite3 database on the host.โฆ
๐ก๏ธ **CWE-35**: Improper Limitation of a Pathname to a Restricted Directory. ๐ **Flaw**: No validation on database filenames. ๐ **Result**: Allows accessing arbitrary files outside intended scope.
Q3Who is affected? (Versions/Components)
๐ข **Vendor**: clidey. ๐ฆ **Product**: WhoDB. ๐ **Affected**: Versions **0.45.0 and earlier**. ๐ **Type**: Open-source data browser.
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Privileges**: **Unauthenticated** access required. ๐๏ธ **Data**: Can open **any** SQLite3 DB on the server. ๐ **Scope**: Host system files exposed. ๐ **Severity**: High Confidentiality & Integrity impact.