← Back to CVE List

CVE-2023-26563

Published: 2023-07-12T21:15Z
Last Modified: 2024-11-21T07:51Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file, download any directory, delete any file, upload any file to any directory accessible by the web server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt