Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal
Vulnerability Description
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 contains a patch for the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
PwnDoc 安全漏洞
Vulnerability Description
PwnDoc是PwnDoc开源的一个渗透测试报告生成器。 PwnDoc存在安全漏洞。攻击者利用该漏洞可以读取系统上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A