What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.
Explanation of Vulnerability in Simple Terms
Product Feed Manager versions up to 7.3.15 contain a path traversal vulnerability that allows high-privilege users to read files outside the intended directory. An attacker with administrative access can craft requests to access sensitive files on the server. The vulnerability requires high privileges and does not affect availability, but can expose configuration files and other sensitive data.
What an attacker can do
Read files outside the intended directory on the server.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access sensitive server files.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities