Menyoo
- < 2.0
A directory traversal vulnerability has been identified in Menyoo version 2.0, prior to commit 729aa48. This vulnerability allows local attackers to execute arbitrary code by exploiting the file management features of the Spooner, VehicleSpawner, WeaponOptions, and PedComponentChanger modules. The issue arises from insufficient validation of user-provided file and folder names, which can be manipulated to traverse directories and execute malicious code.
Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.
The vulnerability can be reproduced by creating or renaming files and folders in the affected Menyoo modules without proper validation of the input. This can be done by including directory traversal sequences or invalid characters in the file or folder names, which the application will not properly sanitize before processing.
Users can update to Menyoo version 2.0 through commit 729aa48, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.