CVE-2015-4425

Published Aug 18, 2015

Last updated 9 years ago

Overview

Description
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
4.9
Impact score
4.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Configurations