CVE-2023-38633

CVE-2023-38633

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

Source: CVE-2023-38633

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다