SourceCodester Employee and Visitor Gate Pass Logging System
cpe:2.3:a:employee_and_visitor_gate_pass_logging_system_project:employee_and_visitor_gate_pass_logging_system:*:*:*:*:*:*:*
- 1.0
A directory traversal vulnerability has been identified in SourceCodester Employee and Visitor Gate Pass Logging System version 1.0. This vulnerability allows remote attackers to access and download any file from multiple sub-directories, including 'database', 'dist', 'libs', and 'uploads'. The issue arises because the application fails to properly sanitize user input, enabling unauthorized access to potentially sensitive information on the server.
Exploitation of this vulnerability leads to unauthorized access to files on the server, allowing attackers to download and potentially misuse sensitive information.
The vulnerability can be reproduced by sending a request to the '/employee_gatepass/dist/' route. This can be done using a web browser or a tool like cURL, without any authentication. The response will include a directory listing, exposing files that can be downloaded.
It is recommended to change the configuration settings to prevent directory traversal attacks.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.