Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSouthrivertech Titan Mft Server
APPSouthrivertech< 2.0.18Southrivertech Titan Sftp Server
APPSouthrivertech< 2.0.18
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
Related vulnerabilities
CVE-2023-45687HIGH8.8same product
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Wi...
CVE-2023-45688MEDIUM4.3same product
Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allo...
CVE-2023-45689MEDIUM6.5same product
Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows an...
CVE-2023-45690MEDIUM4.9same product
Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user ...
CVE-2022-34005CRITICAL9.8PL ✓same vendor
RCE przez zakodowane hasło konta SA w TitanFTP NextGen