FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://github.com/EmreOvunc/FileRun-Vulnerabilities/ | third party advisory exploit |
https://filerun.com/changelog | release notes vendor advisory |
https://emreovunc.com/blog/en/FileRun-DirectoryListing-3.png | third party advisory exploit |
https://github.com/EmreOvunc/FileRun-Vulnerabilities/issues/3 | third party advisory |