Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56606
HistoryJul 13, 2022 - 12:00 a.m.

CarceresBE path traversal vulnerability

2022-07-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
carceresbe
sks
parking management system
path traversal
vulnerability
flask's send_file function
attacker
arbitrary files
file system.

EPSS

0.002

Percentile

62.0%

CarceresBE is an SKS parking management system backend open sourced by Delor4. CarceresBE 1.0 and earlier versions have a path traversal vulnerability that stems from a failure of Flask’s send_file function to properly filter special elements in a resource or file path, which could be exploited by an attacker to access arbitrary files stored on the file system and directories stored on the file system.

EPSS

0.002

Percentile

62.0%

Related for CNVD-2022-56606