Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read
Vulnerability
A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the maxtime/api/sql/sql.lua file.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially exposing confidential information.
Remediation
No official patch has been communicated by the vendor. However, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0, until a patch is available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
