CVE-2023-46863 | Peppermint Ticket Management up to 0.2.3 POST Request download filepath path traversal (Issue 108 / EUVD-2023-51029)
A vulnerability, which was classified as problematic, was found in Peppermint Ticket Management up to 0.2.3. Affected by this vulnerability is an unknown functionality of the file /api/v1/users/file/download of the component POST Request Handler. Executing a manipulation of the argument filepath can lead to relative path traversal.
This vulnerability is handled as CVE-2023-46863. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.