Skip to content

Local File Enumeration when accessing /list

High
Linbreux published GHSA-w4cf-92x9-v8w2 Sep 4, 2022

Package

wiki.py (wikmd)

Affected versions

< 1.7.0

Patched versions

>= 1.7.1

Description

Impact

Wikmd is vulnerable to a Path Traversal vulnerability when accessing /list/path:folderpath and discloses lists of files located on the server including sensitive data.

Severity

High

CVE ID

CVE-2022-36081

Weaknesses

Credits