What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3.
Explanation of Vulnerability in Simple Terms
CYAN Backup versions 2.5.3 and earlier contain a flaw that allows high-privilege users to read sensitive data they should not access. The vulnerability requires administrator-level access and does not affect data integrity or availability. A patch version has not been publicly identified.
What an attacker can do
Read sensitive information the attacker should not have access to.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access confidential backup or system data.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities