← Back

CVE-2024-39303

nvd nist
Published: Jul 1, 2024Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects.

Affected (1)

Products: Weblate: Weblate
1 product
Weblate
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.14 to 5.6.2

References (4)

Timeline

No history available yet.