Intel

AIKIDO-2024-10356

craftcms/cms is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 23, 2024

94

Critical Risk

This Affects:

phpcraftcms/cms
4.0.0 - 4.12.7
Fixed in 4.12.8
5.0.0 - 5.4.8
Fixed in 5.4.9
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to path traversal via the dataUrl method. This vulnerability allows attackers to manipulate file paths and access files outside the intended directory, potentially leading to unauthorized access to sensitive files.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Path Traversal in versions 4.0.0 - 4.12.7 and 5.0.0 - 5.4.8.

How to fix this

Upgrade the craftcms/cms library to a patch version.