What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.
Explanation of Vulnerability in Simple Terms
Media Library Folders versions up to 8.1.8 contain a path traversal vulnerability that allows authenticated users to read files outside the intended directory structure. An attacker with low-level site access can navigate the file system to access sensitive files. This vulnerability requires an active site account but does not require administrator privileges.
What an attacker can do
Read arbitrary files on the server outside the media library directory.
Potential impact on your site
Sensitive files (config, database backups, private keys) may be exposed to any authenticated user, not just admins.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., contributor or subscriber role).
Key dates
External resources
Related vulnerabilities