GHSA-7jr3-j3rm-rx7wHighCVSS 6.5

plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/.

🔗 References (6)