Filtered by vendor Mercadoenlineaback Project Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-31505 1 Mercadoenlineaback Project 1 Mercadoenlineaback 2022-07-15 9.3 Critical
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.