Skip to content

Conversation

@nishfath
Copy link
Owner

@nishfath nishfath commented May 1, 2025

Qwiet AI AutoFix

This PR was created automatically by the Qwiet AI AutoFix tool.
As long as it is open, subsequent scans and generated fixes to this same branch will be added to it as new commits.

Each commit fixes one vulnerability.

Some manual intervention might be required before merging this PR.

Project Information

Findings/Vulnerabilities Fixed

Finding 45: Remote Code Execution: Command Injection Through Attacker-controlled Data via cmd in Rce.CommandExec

Vulnerability Description

Attacker-controlled data is used in a shell command without undergoing escaping or validation. This indicates a command injection vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-94: Remote Code Execution
Commits/Files Changed

Finding 67: Directory Traversal: Attacker-controlled Data Used in File Path via url in SSRF.openStream

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 66: Directory Traversal: Attacker-controlled Data Used in File Path via url in SSRF.openStream

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 64: Directory Traversal: Attacker-controlled Data Used in File Path via filepath in PathTraversal.getImage

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 63: Directory Traversal: Attacker-controlled Data Used in File Path via filepath in PathTraversal.getImageSec

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 62: Directory Traversal: Attacker-controlled Data Used in File Path via multifile in FileUpload.uploadPicture

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 60: Directory Traversal: Attacker-controlled Data Used in File Path via multifile in FileUpload.uploadPicture

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 65: Directory Traversal: Attacker-controlled Data Used in File Path via url in SSRF.ImageIO

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Finding 61: Directory Traversal: Attacker-controlled Data Used in File Path via multifile in FileUpload.uploadPicture

Vulnerability Description

Attacker-Controlled input data is used as part of a file path to write a file without escaping or validation. This indicates a directory traversal vulnerability.

  • Severity: critical
  • CVSS Score: 9 (critical)
  • CWE: CWE-22: Directory Traversal
Commits/Files Changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants