← Back to CVE List

CVE-2018-20437

Published: 2018-12-25T15:29Z
Last Modified: 2024-11-21T04:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data > MITRE Terms of Use apply – see LICENSE‑MITRE.txt