2.4.4
6 years ago
4 days ago
Known vulnerabilities in the psitransfer package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Directory Traversal through the Workarounds
How to fix Directory Traversal? Upgrade | <2.4.3 |
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Zip Slip in the archive download functionality in How to fix Zip Slip? Upgrade | <2.3.1 |
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type on the endpoint, which allows users to create a path for uploading a file in a file distribution. An attacker can influence those users who access the file distribution subsequently and insert files with malicious or phishing content by adding arbitrary files to the distribution. How to fix Unrestricted Upload of File with Dangerous Type? Upgrade | <2.2.0 |
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type due to the absence of restrictions on the endpoint designed for uploading files, an attacker who has received the id of a file distribution can alter the files within this distribution. Note: This vulnerability enables an attacker to affect those users who access the file distribution subsequently, potentially slipping in files with malicious or phishing content. How to fix Unrestricted Upload of File with Dangerous Type? Upgrade | <2.2.0 |
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type due to the absence of restrictions on the endpoint, which allows the creation of a path for uploading a file in a file distribution. An attacker can add arbitrary files to the distribution by sending a POST request to How to fix Unrestricted Upload of File with Dangerous Type? Upgrade | <2.2.0 |
psitransfer is a Simple open source self-hosted file sharing solution Affected versions of this package are vulnerable to Unrestricted Upload of File with Dangerous Type due to the absence of restrictions on the endpoint designed for uploading files. An attacker who receives the id of a file distribution can alter the files within this distribution by sending a How to fix Unrestricted Upload of File with Dangerous Type? Upgrade | <2.2.0 |