PoC Index

CVE-2023-35844

HIGH 7.5EPSS 6.3%

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
6.34% chance of exploitation in the next 30 days, 93th percentile
Nuclei
high · CWE-22
Published
2023-06-19
Updated
2024-12-11

Proof-of-concept exploits (3)

Nuclei templates (1)

Exploit collections (1)

References

Related