CVE-2022-31505
11.07.2022, 01:15
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
| Vendor | Product | Version |
|---|---|---|
| mercadoenlineaback_project | mercadoenlineaback | 𝑥 ≤ 2022-05-04 |
𝑥
= Vulnerable software versions