ID:10509 - Exploit for Input validation error in Werkzeug - CVE-2019-14322

 
Main Vulnerability Database Exploits ID:10509 - Exploit for Input validation error in Werkzeug - CVE-2019-14322

ID:10509 - Exploit for Input validation error in Werkzeug - CVE-2019-14322

Published: September 20, 2024


Vulnerability identifier: #VU19553
Vulnerability risk: Medium
CVE-ID: CVE-2019-14322
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Werkzeug

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to access arbitrary files on the target system.

The vulnerability exists due to the "SharedDataMiddleware" mishandles drive names (such as C:) in Windows pathnames. A remote attacker can access arbitrary files on the target system.


Remediation

Install updates from vendor's website.