What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetThemeCore jet-theme-core.This issue affects JetThemeCore: from n/a through < 2.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetThemeCore jet-theme-core.This issue affects JetThemeCore: from n/a through < 2.2.1.
Explanation of Vulnerability in Simple Terms
JetThemeCore versions up to 2.2.1 contain a path traversal vulnerability that allows authenticated users to cause a denial of service by accessing files outside the intended directory. The vulnerability requires low-level user privileges and network access. Site availability can be disrupted through resource exhaustion or service interruption.
What an attacker can do
Disrupt site availability by traversing the file system and triggering resource exhaustion or service failure.
Potential impact on your site
Site may become unavailable or unresponsive if an authenticated user exploits this path traversal flaw.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities