PT-2024-12725 · Unknown · Averta Phlox Portfolio

Rafie Muhammad

·

Published

2024-05-17

·

Updated

2024-05-17

·

CVE-2023-38399

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Averta Phlox Portfolio versions prior to 2.3.1
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as 'Path Traversal', which allows PHP Local File Inclusion. This means that an attacker could potentially access and include files from outside the intended directory, leading to security issues.
Recommendations For versions prior to 2.3.1, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-38399

Affected Products

Averta Phlox Portfolio