Executive brief
The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
Affected products
- PyPI radicale
Junglewise Threat Intelligence
CVE-2015-8747 · Severity: low · CVSS 3 · Published 2016-02-03
Technologies: radicale (PyPI). Vendors: PyPI.
The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.