What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.
Explanation of Vulnerability in Simple Terms
JupiterX through version 3.0.0 contains a path traversal vulnerability that allows authenticated users to read files outside the intended directory. An attacker with low-level access can traverse the file system to access sensitive files. The vulnerability also permits limited modification and disruption of availability. Update to a version newer than 3.0.0.
What an attacker can do
Read arbitrary files on the server and modify or delete some files.
Potential impact on your site
Sensitive files (config, database credentials, private keys) may be exposed to authenticated attackers.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities