
We found results for “”
CVE-2024-22723
Good to know:

Date: February 27, 2024
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Top Fix

Upgrade Version
Upgrade to version fisharebest/webtrees - 2.1.19;fisharebest/webtrees - dev-dependabot/composer/league/flysystem-2.1.1;fisharebest/webtrees - dev-dependabot/npm_and_yarn/follow-redirects-1.14.8;fisharebest/webtrees - dev-dependabot/composer/composer/composer-2.1.9
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |