{ "id": "CVE-2023-46863", "sourceIdentifier": "cve@mitre.org", "published": "2023-10-30T00:15:39.157", "lastModified": "2023-10-30T11:54:30.703", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request." } ], "metrics": {}, "references": [ { "url": "https://github.com/Peppermint-Lab/peppermint/issues/108", "source": "cve@mitre.org" } ] }