CVE-2023-46864: Peppermint

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.

Affected products

Published 2023-10-30. Last modified 2026-06-17.