这是indexloc提供的服务,不要输入任何密码
Skip to content

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') #5522

@smarfer

Description

@smarfer

The PGAdmin ERD Tool can open files on the server. The input is vulnerable to directory traversal. To abuse
this, the POST can be altered:

Steps to reproduce:

  1. Open Tools -> ERD Tool
  2. Choose Open File
  3. Change POST (/pgadmin4/sqleditor/load_file/ )

Screenshot 2022-11-14 at 11 44 41

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions