External Control of File Name or Path in Canto Extension - #VU77340

 

External Control of File Name or Path in Canto Extension - #VU77340

Published: June 15, 2023


Vulnerability identifier: #VU77340
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to download arbitrary files.

The vulnerability exists due to application allows an attacker to control path of the files to delete. A remote user can send a specially crafted HTTP request and download arbitrary files on the system, leading to arbitrary code execution.


Affected software

Canto Extension

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins