Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://support.synapsoft.co.kr:50000/skin/try_pdfocus/index.html | product |
https://github.com/S4nshine/CVE-2023-23169 | third party advisory exploit |