Path traversal in FlightCrew - CVE-2019-13241
Published: June 10, 2021
FlightCrew
Sigil-Ebook
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in filenames when extracting data from ZIP archives. A remote attacker can trick the victim to open a specially crafted archive and overwrite arbitrary files on the system.