Vulnerability Description
A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gladysassistant | Gladys Assistant | <= 4.26.1 |
Related Weaknesses (CWE)
References
- https://blog.moku.fr/cves/CVE-2023-43256/Third Party Advisory
- https://blog.moku.fr/cves/CVE-unassigned/Third Party Advisory
- https://github.com/GladysAssistant/Gladys/commit/f27d0ea4689c3deca5739b5f9ed45a2Patch
- https://blog.moku.fr/cves/CVE-2023-43256/Third Party Advisory
- https://blog.moku.fr/cves/CVE-unassigned/Third Party Advisory
- https://github.com/GladysAssistant/Gladys/commit/f27d0ea4689c3deca5739b5f9ed45a2Patch
FAQ
What is CVE-2023-43256?
CVE-2023-43256 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
How severe is CVE-2023-43256?
CVE-2023-43256 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43256?
Check the references section above for vendor advisories and patch information. Affected products include: Gladysassistant Gladys Assistant.