Description

Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

INFO

Published Date :

2024-11-13T00:00:00.000Z

Last Modified :

2024-11-21T16:45:14.070Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-48510 vulnerability.

Vendors Products
Dotnetzip.semverd Project
  • Dotnetzip.semverd
Mihula
  • Prodotnetzip
Nuget
  • Dotnetzip

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact