A vulnerability has been identified in rdiffWeb, which could be exploited by attackers to bypass security checks and gain knowledge of sensitive information. This issue is caused by an input validation error in the "rdw_helpers.py" script when processing the "path" parameter, which could be exploited to conduct directory traversal attacks and gain unauthorized access to arbitrary files on a vulnerable server.
Vulnerable Products
Vulnerable Software: rdiffWeb version 0.3.5 and prior