CVE-2026-96440

Summary

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.

Affected Software

VendorProductVersion RangeStatus
Flowring Technology CorpAgentflow 4.00 < 2023/03/24affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)

References