Local File Overwrite Vulnerability in OnionShare by Onion
CVE-2018-19960
7HIGH
What is CVE-2018-19960?
The debug_mode function within web/web.py in OnionShare prior to version 1.4 utilizes the /tmp/onionshare_server.log file for logging when --debug is enabled. This implementation flaw may enable local attackers to overwrite files or access sensitive data, posing significant risks to system integrity and data confidentiality.
