NA

CVE-2023-52289

Published: 13/01/2024 Updated: 24/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in the flaskcode package up to and including 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows malicious users to write to arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

sujeetkv flaskcode