CVE-2015-10030 MEDIUM

CVE-2015-10030: SUKOHI Surpass Surpass.php pathname traversal

Vendor Sukohi
Product Surpass
Weakness CWE-21
Published January 8, 2023
Last update April 9, 2025

CVSS base score

5.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability has been found in SUKOHI Surpass and classified as critical. This vulnerability affects unknown code of the file src/Sukohi/Surpass/Surpass.php. The manipulation of the argument dir leads to pathname traversal. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as d22337d453a2a14194cdb02bf12cdf9d9f827aa7. It is recommended to upgrade the affected component. VDB-217642 is the identifier assigned to this vulnerability.

Key dates

02Disclosure timeline

January 8, 2023 CVE published
April 9, 2025 Record updated