Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain or delete arbitrary files on the server (within the privilege of the Redmine process).
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T03:37:04.600Z
Reserved: 2024-05-23T02:01:25.701Z
Link: CVE-2024-36267
Updated: 2024-08-02T03:37:04.600Z
Status : Awaiting Analysis
Published: 2024-05-30T06:15:09.067
Modified: 2024-11-21T09:21:57.790
Link: CVE-2024-36267
No data.
OpenCVE Enrichment
No data.
Weaknesses