Loading
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
Use CWE-22, Unbit vendor hub and Uwsgi product page to widen CVE-2018-7490 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-6758 and CVE-2023-27522 for nearby disclosures in the same product family.