7.5
CVSSv3

CVE-2023-52288

Published: 13/01/2024 Updated: 24/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in the flaskcode package up to and including 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows malicious users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

sujeetkv flaskcode