What the vulnerability does
01Description
Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.
Explanation of Vulnerability in Simple Terms
FULL Customer versions up to 3.1.25 contain a flaw that allows authenticated users to read sensitive data they should not have access to. The vulnerability requires a valid user account but no special privileges. An attacker with low-level access can retrieve confidential information from the application without modifying or disrupting service.
What an attacker can do
Read sensitive data they should not have access to.
Potential impact on your site
User data confidentiality is at risk if accounts are compromised or if untrusted users have access.
Conditions required to exploit
Valid user account with low-level privileges; network access to the application.
Key dates
External resources
Related vulnerabilities