cve/2024/CVE-2024-55602.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2024-55602

Description

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (../) sequences into the file extension property to read arbitrary files on the system. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 contains a patch for the issue.

POC

Reference

Github

No PoCs found on GitHub currently.