CVE-2018-20303
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
- Affected products
- Gogs
- Gogs
- < 0.11.82.1218
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2018-12-20
CVE-2018-20303 at NVD
1 known exploit for CVE-2018-20303
Proof-of-concept code and exploit modules indexed by Sploitus