Executive brief
Follett Destiny Library Manager, a widely used platform for managing school library resources and assets, contains a security flaw that allows unauthorized individuals to access sensitive files. By sending a specially crafted web request, an attacker can bypass security restrictions to read internal system and application files. This could lead to the exposure of configuration data, credentials, or other private information stored on the server.
Technical details
A directory traversal vulnerability (CWE-22) exists in Follett Software's Destiny Library Manager version 22.0.2_rc1. The flaw is located within the handling of the 'image' parameter, where the application fails to properly sanitize user-supplied input before using it in file path operations. An unauthenticated remote attacker can exploit this by submitting a crafted URL containing path traversal sequences (e.g., ../) to access files outside of the intended web directory. This allows for the unauthorized retrieval of sensitive system and application configuration files. The issue is addressed in version 22.5 AU1.
Affected products
- Follett Software Destiny Library Manager 22.0.2_rc1
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
- 2026-05-22: patched: Fixed in v.22.5 AU1