Path Traversal Vulnerability in XXL-CONF by XXL-JOB
CVE-2018-20094
7.5HIGH
What is CVE-2018-20094?
A path traversal vulnerability exists in XXL-CONF 1.6.0, allowing an attacker to exploit the keys parameter and gain unauthorized access to sensitive configuration files. This flaw, linked to ConfController.java and PropUtil.java, can be exploited by manipulating file paths, enabling attackers to bypass security mechanisms and download arbitrary files from the server.
