VDB
Sign up
HIGH

GHSA-277f-37gw-9gmq

raspap-webgui has a Directory Traversal vulnerability

Quick fix

GHSA-277f-37gw-9gmq — billz/raspap-webgui: upgrade to the fixed version with the command below.

composer require billz/raspap-webgui:^3.3.6

Details

RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/billz/raspap-webgui
Introduced in: 0Fixed in: 3.3.6
Fixcomposer require billz/raspap-webgui:^3.3.6

References