Description
Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-22
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-15T16:16:11.650Z
1 month agoLast modified
2026-01-21T14:45:48.207Z
1 month ago