Path Traversal in Q-Free MaxTime <= 2.11.0 Enables Sensitive File Overwrite
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote malicious user to overwrite sensitive files via crafted HTTP requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
q-free maxtime |