VYPR
Critical severityNVD Advisory· Published Oct 25, 2022· Updated Apr 22, 2025

Gin-vue-admin arbitrary file upload vulnerability caused by path traversal

CVE-2022-39345

Description

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/flipped-aurora/gin-vue-admin/serverGo
< 2.5.42.5.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.