Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
kerwincui FastBee Tool Download Endpoint ToolController.java ToolController.download path traversal
Vulnerability Description
A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/controller/ToolController.java of the component Tool Download Endpoint. The manipulation of the argument fileName results in path traversal. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
FastBee 路径遍历漏洞
Vulnerability Description
FastBee是中国FastBee开源的一个物联网平台。 FastBee 1.2.1及之前版本存在路径遍历漏洞,该漏洞源于组件Tool Download Endpoint中文件springboot/fastbee-open-api/src/main/java/com/fastbee/data/controller/ToolController.java的函数ToolController.download对参数fileName的操作,可能导致路径遍历。
CVSS Information
N/A
Vulnerability Type
N/A