CVE-2024-47818 | Saltcorn up to 1.0.0-beta.15 POST Parameter sync/clean_sync_dir dir_name path traversal (GHSA-43f3-h63w-p6f6)
A vulnerability was found in Saltcorn up to 1.0.0-beta.15. It has been declared as critical. This vulnerability affects unknown code of the file sync/clean_sync_dir of the component POST Parameter Handler. The manipulation of the argument dir_name leads to path traversal.
This vulnerability was named CVE-2024-47818. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.