PT-2024-20695 · Xenforo · Xenforo

Egidio Romano

·

Published

2024-02-02

·

Updated

2025-05-08

·

CVE-2024-25006

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.2.14
Description The issue allows Directory Traversal with write access by an authenticated user who has permissions to administer styles. This is possible when using a ZIP archive for Styles Import.
Recommendations For versions prior to 2.2.14, update to version 2.2.14 or later to resolve the issue. As a temporary workaround, consider restricting the ability to administer styles and limiting the use of ZIP archives for Styles Import until a patch is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-25006

Affected Products

Xenforo