Skip to main content

Vendor archive

travel_blahg_project CVEs

Beta · best-effort

1 CVEs tagged to vendor travel_blahg_project1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-31532

Published Jul 11, 2022

The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1