Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://www.cartadis.com/gespage-website/ | third party advisory |
https://www.gespage.com | vendor advisory |
https://support.gespage.com/fr/support/solutions/articles/14000130201-security-advisory-gespage-directory-traversal | vendor advisory |
https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_gespage_-_cve-2021-33807.pdf | third party advisory exploit |