Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39012
HistoryJan 26, 2023 - 2:31 a.m.

Path Traversal

2023-01-2602:31:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
path traversal
github.com/go-sonic/sonic
backupwholesite
backup.go
tobackuppath
vulnerability
file path
attacker
directory

EPSS

0.001

Percentile

26.6%

github.com/go-sonic/sonic is vulnerable to Path Traversal. The vulnerability exists because the BackupWholeSite function of backup.go does not properly sanitize the file path in the toBackupPath parameter, allowing an attacker to access files outside the expected directory.

EPSS

0.001

Percentile

26.6%

Related for VERACODE:39012