An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://docs.opswat.com/mdkiosk | product release notes |
https://docs.opswat.com/mdkiosk/release-notes/cve-2023-36658 | release notes vendor advisory |