Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
usap-dc-website 路径遍历漏洞
Vulnerability Description
usap-dc-website是美国Interdisciplinary Earth Data Alliance开源的一个 usap-dc 网站的存储库。包括 javascript 客户端应用程序和 python/flask 服务器端。 usap-dc-website 1.0.1版本存在路径遍历漏洞,该漏洞源于Flask send_file 函数使用不安全。
CVSS Information
N/A
Vulnerability Type
N/A