Path traversal in JSPWiki - CVE-2019-0225
Published: September 24, 2019
JSPWiki
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send s specially crafted URL, access files under the ROOT directory of the application and obtain registered users' details.