Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111288. PoCs published by Curesec Research Team.
AI-analyzed exploit summary This advisory details a directory traversal vulnerability in PivotX 2.3.11, where the `cleanPath` function fails to properly sanitize path inputs, allowing authenticated users to read or delete arbitrary files. The PoC demonstrates bypassing the sanitization via encoded traversal sequences.
Description
PivotX 2.3.11 - Directory Traversal
Exploits (1)
This advisory details a directory traversal vulnerability in PivotX 2.3.11, where the `cleanPath` function fails to properly sanitize path inputs, allowing authenticated users to read or delete arbitrary files. The PoC demonstrates bypassing the sanitization via encoded traversal sequences.