Описание
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
- Improper Limitation of a Pathname to a Restricted Directory: A vulnerability exists in the asset upload functionality that allows users to upload files to directories outside of the intended temporary directory.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2.3 (исключая)
cpe:2.3:a:acquia:mautic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00165
Низкий
4.3 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 4.3
github
12 месяцев назад
Mautic allows Relative Path Traversal in assets file upload
EPSS
Процентиль: 38%
0.00165
Низкий
4.3 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-22