CVE Database
/

CVE-2018-1306

Back to search

CVE-2018-1306

Published: Jun 27, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.

VendorProductVersions

Apache Software Foundation

Apache Pluto

affected
3.0.0

References

45396
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now