Skip to content

exposure of sensitive system files/directories #540

@code5ecure

Description

@code5ecure

In KodExplorer version 4.52 (and 4.52.01), the demo user (default guest account with credentials demo/demo) can access and list the server's physical root directory (e.g., C:\ on Windows/XAMPP or / on Linux) through the explorer/pathList endpoint.

https://github.com/code5ecure/KodExplorer

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions