The XMLUI feature in DSpace prior to 3.6, 4.x prior to 4.5, and 5.x prior to 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
duraspace dspace |