What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through <= 2.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through <= 2.1.1.
Explanation of Vulnerability in Simple Terms
XLSXviewer versions 2.1.1 and earlier contain a path traversal vulnerability that allows an attacker to cause a denial of service by making the application unavailable. The vulnerability requires no authentication or user interaction and can be exploited over the network. The impact is limited to availability; data confidentiality and integrity are not affected.
What an attacker can do
Make the XLSXviewer application unavailable or unresponsive.
Potential impact on your site
The XLSXviewer application may become unavailable or slow to respond to legitimate users.
Conditions required to exploit
Network access to the vulnerable XLSXviewer instance; no authentication required.
Key dates
External resources
Related vulnerabilities