Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability
CVE-2023-52334
What is CVE-2023-52334?
The Allegra application developed by TrackPlus contains a directory traversal vulnerability that allows remote attackers to disclose sensitive information from the affected systems. The flaw specifically resides in the 'downloadAttachmentGlobal' action, where user-supplied paths are not adequately validated prior to being utilized in file operations. This oversight enables attackers, even those who have authenticated, to exploit the issue and potentially expose stored credentials, which could lead to further unauthorized access and compromise of the affected installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Allegra 7.5.0 build 29
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
