Root Path Bypass Vulnerability in Restafary API

Root Path Bypass Vulnerability in Restafary API

CVE-2016-10528 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.

Learn more about our Web App Pen Testing.