What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.
Explanation of Vulnerability in Simple Terms
Rehub versions up to 19.6.1 contain a path traversal vulnerability that allows an attacker to read or write arbitrary files on the server. The vulnerability requires high attack complexity but no authentication. An attacker can access sensitive files, modify site content, or potentially execute code by uploading malicious files to unprotected directories.
What an attacker can do
Read or write arbitrary files on the server, potentially accessing sensitive data or uploading malicious code.
Potential impact on your site
Attackers could steal database credentials, modify site files, inject malware, or compromise user data without needing a site account.
Conditions required to exploit
Network access to the Rehub installation; no authentication required, but exploitation requires specific conditions.
Key dates
External resources
Related vulnerabilities