Letseeqiji Gorobbs Path Traversal Vulnerability in User Avatar Reset Function

Vulnerability

A critical path traversal vulnerability has been identified in Letseeqiji Gorobbs versions through 1.0.8. The issue arises in the API component, specifically within the ResetUserAvatar function of the user.go file. The vulnerability allows for arbitrary file writing by manipulating the filename argument, enabling attackers to traverse directories and write files outside the intended directory structure. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for arbitrary file writing on the server, potentially leading to unauthorized file access or modification.

Reproduction

To reproduce this vulnerability, send a request to the ResetUserAvatar endpoint with a crafted filename parameter that includes directory traversal sequences, such as '../../..', and an id parameter that also includes traversal sequences. This will bypass directory restrictions and allow files to be written to arbitrary locations on the server.

Added: Jul 11, 2025, 5:52 PM
Updated: Jul 11, 2025, 5:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.