CyberRota Analysis
AI-GeneratedWsgiDAV versions 4.3.3 and earlier are vulnerable to a directory traversal attack that allows an attacker to craft a WebDAV request capable of escaping the configured filesystem share root, potentially exposing sensitive files. This vulnerability poses a high risk, particularly for organizations using WsgiDAV for file sharing and collaboration. Users of affected versions should prioritize upgrading to version 4.3.4 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.