First published: Thu Sep 26 2019(Updated: )
Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plutinosoft Platinum | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16903 is a vulnerability that allows Directory Traversal in Platinum UPnP SDK 1.2.0.
CVE-2019-16903 has a severity rating of 5.3, which is considered medium.
CVE-2019-16903 affects Platinum UPnP SDK version 1.2.0.
The CWE for CVE-2019-16903 is CWE-22.
To fix CVE-2019-16903, update your Platinum UPnP SDK installation to a version that is not affected by the vulnerability.