NA

CVE-2022-48285

Published: 29/01/2023 Updated: 03/03/2023
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

loadAsync in JSZip prior to 3.8.0 allows Directory Traversal via a crafted ZIP archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jszip project jszip

Vendor Advisories

Description<!---->A flaw was found in the JSZip package Affected versions of JSZip could allow a remote attacker to traverse directories on the system caused by the failure to sanitize filenames when files are loaded with `loadAsync`, which makes the library vulnerable to a Zip Slip attack By extracting files from a specially crafted archive, an ...