{"id":"CVE-2023-1800","aliases":["GHSA-xq3x-grrj-fj6x","GO-2023-1713"],"url":"https://o3.security/vulnerability/CVE-2023-1800","summary":"sjqzhang go-fastdfs File Upload uploa upload path traversal","details":"A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224768.","published":"2023-04-02T10:31:03.341Z","modified":"2026-07-15T01:49:13.582948482Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/sjqzhang/go-fastdfs","fixedVersion":"1.4.5-0.20230408141131-61cbff5124c6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1800.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1800"},{"type":"ADVISORY","url":"https://vuldb.com/?id.224768"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.224768"},{"type":"EVIDENCE","url":"https://github.com/yangyanglo/ForCVE/blob/main/2023-0x05.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:13.582948482Z"}}