logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-31259

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-31259

Description:
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
Last updated date:
02/17/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/02/2022
Reference url to background

https://github.com/beego/beego/issues/4946

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy