PT-2024-20695 · Xenforo · Xenforo

·

CVE-2024-25006

·

Published

2024-02-02

·

Updated

2025-05-08

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.2.14
Description The issue allows Directory Traversal with write access by an authenticated user who has permissions to administer styles. This is possible when using a ZIP archive for Styles Import.
Recommendations For versions prior to 2.2.14, update to version 2.2.14 or later to resolve the issue. As a temporary workaround, consider restricting the ability to administer styles and limiting the use of ZIP archives for Styles Import until a patch is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25006

Affected Products

Xenforo