CVE-2018-18434: Path Traversal
Published Oct 17, 2018
·Updated
An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component.
Affected Software
2 affected components
Litemall Project Litemall=0.9.0
linlinjava litemall=0.9.0
Remediation
Event History
Oct 17, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·06:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-18434?
CVE-2018-18434 has a moderate severity level due to the potential for arbitrary file downloads.
2
How do I fix CVE-2018-18434?
To fix CVE-2018-18434, upgrade litemall to a version that has addressed this vulnerability.
3
What impact does CVE-2018-18434 have on my system?
CVE-2018-18434 allows attackers to exploit directory traversal vulnerabilities to access unauthorized files.
4
Is CVE-2018-18434 exploitable remotely?
Yes, CVE-2018-18434 can be exploited remotely by an attacker with knowledge of the affected system.
5
What versions are affected by CVE-2018-18434?
CVE-2018-18434 affects litemall version 0.9.0.