Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://www.sitincloud.com/securite/directory-traversal-openbravo-erp/ | third party advisory exploit |
https://grep.blog/directory-traversal-openbravo/ | third party advisory |
https://issues.openbravo.com/view.php?id=41413 | exploit patch vendor advisory |