AxxonSoft Axxon Next Directory Traversal

CVE-2018-7467

AxxonSoft Axxon Next was affected by a client directory traversal issue using an initial /css//..%2f substring in a URI.

Security consequence

Directory traversal flaws can allow a remote user to escape the intended content directory and request files that the application was not designed to expose. Canonicalize paths, constrain access to an explicit root, reject traversal sequences after decoding, and authorize the requested resource server-side.

References

Back to security insights