GHSA-9r62-vc7q-pm8jHigh
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the ...
🔗 CVE IDs covered (1)
📋 Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.