Vulnerabilities/

PsiTransfer: Violation of the integrity of file distribution

Severity:
Medium

Description

Summary The absence of restrictions on the endpoint, which allows you to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution.

Details Vulnerable endpoint: POST /files

PoC

  1. Create a file distribution.

Recommendation

Update the psitransfer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
psitransfer
Anything's wrong? Let us know Last updated on April 09, 2024

This issue is available in SmartScanner Professional

See Pricing