Back

HIGH

An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05

Published Dec 25, 2018

Description

An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 25, 2018
Updated Aug 5, 2024
Reserved Dec 25, 2018
CISA Vulnrichment
Updated Apr 29, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a