External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Link | Tags |
---|---|
https://huntr.dev/bounties/396785a0-7bb6-4db4-b4cb-607b0fd4ab4b | patch exploit third party advisory issue tracking |
https://github.com/unilogies/bumsys/commit/1b426f58a513194206d0ea8ab58baf1461e54978 | patch |