PT-2017-18593 · Flatcore · Flatcore

Pradeepch99

·

Published

2017-05-10

·

Updated

2017-05-17

·

CVE-2017-8868

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions flatCore version 1.4.7
Description The issue allows file deletion through directory traversal in the delete parameter to "acp/acp.php". The risk might be limited to requests submitted through CSRF.
Recommendations For flatCore version 1.4.7, consider restricting access to the "acp/acp.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the delete parameter in the affected endpoint until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8868

Affected Products

Flatcore