Vulnerability Description
Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sei-Info | Rakrak Document Plus | >= 3.2.0.0, < 6.1.1.3a |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN46895889/Third Party Advisory
- https://rakrak.jp/RakDocSupport/rkspServletProduct
- https://jvn.jp/en/jp/JVN46895889/Third Party Advisory
- https://rakrak.jp/RakDocSupport/rkspServletProduct
FAQ
What is CVE-2023-49108?
CVE-2023-49108 is a vulnerability with a CVSS score of 8.8 (HIGH). Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or de...
How severe is CVE-2023-49108?
CVE-2023-49108 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49108?
Check the references section above for vendor advisories and patch information. Affected products include: Sei-Info Rakrak Document Plus.