What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0.
Explanation of Vulnerability in Simple Terms
SP Blog Designer version 1.0.0 and earlier contains a vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability requires network access and high attack complexity. No patch is currently available; administrators should contact the vendor for updates or consider alternative solutions.
What an attacker can do
Read sensitive data, modify content, or disrupt the site's availability.
Potential impact on your site
Authenticated users can access confidential information, alter blog content, or cause service disruption.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities