What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.
Explanation of Vulnerability in Simple Terms
LWS Affiliation versions up to 2.2.6 contain a path traversal vulnerability that allows an attacker to read or write arbitrary files on the server. The vulnerability requires high attack complexity but no authentication or user interaction. An attacker can access sensitive files, modify site content, or potentially execute code depending on file permissions.
What an attacker can do
Read or write arbitrary files on the server, potentially accessing sensitive data or modifying site files.
Potential impact on your site
Attackers could steal configuration files, database credentials, or modify site files without needing a user account.
Conditions required to exploit
Network access to the vulnerable application; no authentication required, but exploitation requires specific conditions.
Key dates
External resources
Related vulnerabilities