CVE-2022-31501
11.07.2022, 01:15
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
| Vendor | Product | Version |
|---|---|---|
| onyxforum_project | onyxforum | 𝑥 ≤ 2022-05-04 |
𝑥
= Vulnerable software versions
References