A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /conv/community. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://vuldb.com/?id.313285 | vdb entry third party advisory |
https://vuldb.com/?ctiid.313285 | vdb entry signature permissions required third party advisory |
https://vuldb.com/?submit.593615 | vdb entry third party advisory |
https://github.com/OpenBMB/XAgent/issues/415 | exploit issue tracking third party advisory |