Security Advisory
CVE-2022-25297
7.5
HIGH
Vulnerability Description
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.
Published Date
February 21, 2022
Official Source
NIST NVD Advisory