Files
CVEs-PoC/2019/CVE-2019-0207.md
2025-09-29 21:09:30 +02:00

853 B

CVE-2019-0207

Description

Tapestry processes assets /assets/ctx using classes chain StaticFilesFilter -> AssetDispatcher -> ContextResource, which doesn't filter the character \, so attacker can perform a path traversal attack to read any files on Windows platform.

POC

Reference

No PoCs from references.

Github