Description
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Sharing-Sassy Social Share Cross-Site Scripting (3.3.3)
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31986)
Joomla Missing Authorization Vulnerability (CVE-2020-10239)
Drupal Core 9.3.x Remote Code Execution (9.3.0 - 9.3.18)
Cherokee Improper Input Validation Vulnerability (CVE-2009-4489)