CVE-2024-34995: Svnwebui

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com.cym.controller.UserController#importOver. This vulnerability allows attackers to delete arbitrary files via a crafted POST request.

Affected products

Published 2024-05-24. Last modified 2026-06-17.