CyberRota Analysis
AI-GeneratedThe vulnerability allows remote authenticated users to exploit a path traversal flaw in the /WebAgenda/download/uploadFile.jsp API of Flowring Agentflow 4.0, enabling them to write files to arbitrary locations outside the designated upload directory. This could lead to unauthorized file access or manipulation, posing a significant risk to the integrity and confidentiality of the system. Organizations using affected versions should prioritize remediation to mitigate potential data breaches or system compromise.
Original NVD Description
Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.