CVE-2023-0454 Information
Feb 02, 2023
cve
Description
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.
Reference
https://fluidattacks.com/advisories/slushii/ https://github.com/Orangescrum/orangescrum/
Share on: