What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.
Explanation of Vulnerability in Simple Terms
CataBlog versions up to 1.7.0 contain a path traversal vulnerability that allows high-privilege users to manipulate file paths and cause service disruption or limited data modification. The vulnerability requires administrator-level access and does not affect data confidentiality. Affected installations should update to a version newer than 1.7.0.
What an attacker can do
Disrupt the site's availability or modify files through manipulated file paths.
Potential impact on your site
An admin account compromise could lead to site downtime or unauthorized file modifications.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities