漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files
Vulnerability Description
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, allowing an authenticated attacker with any role or permission level to traverse out of the intended document directory and download arbitrary files accessible to the application. This includes, but is not limited to, application log files containing sensitive information and application binaries.
CVSS Information
N/A
Vulnerability Type
相对路径遍历
Vulnerability Title
Wertheim SafeController Software for VAULT ROOMS 路径遍历漏洞
Vulnerability Description
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在路径遍历漏洞,该漏洞源于对/safe/selfservice/openselfservicedocument端点中documentName参数的路径处理不当,可能导致经过身份验证的攻击者越出预期文档目录并下载任意文件。
CVSS Information
N/A
Vulnerability Type
N/A