What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3.
Explanation of Vulnerability in Simple Terms
WOLF versions up to 1.0.8.3 contain a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server. An attacker with high-level privileges can bypass directory restrictions and access sensitive files outside the intended application directory. This affects confidentiality but not system integrity or availability.
What an attacker can do
Read arbitrary files on the server filesystem outside the application directory.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access sensitive files like configuration files, database credentials, or private keys.
Conditions required to exploit
Attacker must have administrator-level privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities