Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-31493

Опубликовано: 13 мая 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the collection() helper or $kirby->collection() method with a dynamic collection name (such as a collection name that depends on request or user data). Sites that only use fixed calls to the collection() helper/$kirby->collection() method (i.e. calls with a simple string for the collection name) are not affected. A missing path traversal check allowed attackers to navigate and access all files on the server that were accessible to the PHP process, including files outside of the collections root or even outside of the Kirby installation. PHP code within such files was executed. Such attacks first require an attack vector in the site code that is caused by dynamic collection names, such as collection('tags-' . get('tags')). It generally also requires knowledge of the site structure and the server's file system by the attacker, a

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия до 3.9.8.3 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 3.10.0 (включая) до 3.10.1.2 (исключая)
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.7.1 (исключая)

EPSS

Процентиль: 39%
0.00176
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

github
9 месяцев назад

Kirby vulnerable to path traversal of collection names during file system lookup

EPSS

Процентиль: 39%
0.00176
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22