Back to search
CVE-2022-36943
Published: Jan 3, 2023
Modified: Apr 10, 2025
PUBLISHED
Description
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
| Vendor | Product | Versions |
|---|---|---|
ZipArchive | SSZipArchive | affected unspecified - <= 2.5.3 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now