← Back

Tipask

tipask

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Tipask
tipask

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tipask
1Tipask
Jun 17, 2026
May 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing i...Show more
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.Show less