kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://elixirforum.com/t/kitto-a-framework-for-interactive-dashboards/2089/13 | third party advisory |