Jammy928 CoinExchange_CryptoExchange_Java Path Traversal Vulnerability in File Upload Component
Vulnerability
A critical path traversal vulnerability has been identified in jammy928 CoinExchange_CryptoExchange_Java versions prior to 8adf508b996020d3efbeeb2473d7235bd01436fa. The issue arises in the file UploadFileUtil.java, specifically within the uploadLocalImage function, where improper handling of the filename argument allows for directory traversal. This vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability allows for path traversal, potentially leading to unauthorized file access or manipulation.
Reproduction
To reproduce this vulnerability, send a request to the file upload endpoint with a crafted filename that includes path traversal sequences. This will exploit the vulnerability by traversing directories and accessing files outside the intended upload directory.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
