com.zrlog.plugin.backup.Application
cpe:2.3:a:zrlog:zrlog:*:*:*:*:*:*:*
- 3.0.31
A directory traversal vulnerability has been identified in the Zrlog backup-sql-file plugin, version 3.0.31. This vulnerability allows remote attackers to access sensitive information by exploiting the BackupController.java file. The issue arises because the file parameter is not properly sanitized, enabling arbitrary file downloads.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server, potentially including environment variables or other critical information.
To reproduce this vulnerability, send a request to the '/admin/plugins/backup-sql-file/downfile' endpoint with a crafted file parameter that includes directory traversal sequences. The server will respond with the contents of the specified file, bypassing normal file access restrictions.
Users are advised to update to version 3.0.32 of the Zrlog backup-sql-file plugin, which addresses the directory traversal vulnerability by sanitizing user input to prevent unauthorized file access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.