Files
CVEs-PoC/2019/CVE-2019-11831.md
T
2024-05-26 14:27:05 +02:00

728 B

CVE-2019-11831

Description

The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

POC

Reference

No PoCs from references.

Github