What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.This issue affects Sogrid: from n/a through <= 1.5.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.This issue affects Sogrid: from n/a through <= 1.5.6.
Explanation of Vulnerability in Simple Terms
Sogrid versions up to 1.5.6 contain a path traversal vulnerability that allows attackers to read or modify files on the server. An attacker must trick a user into visiting a malicious link or page. This can expose sensitive configuration files, database credentials, or allow modification of application files.
What an attacker can do
Read or modify files on the server outside the intended directory.
Potential impact on your site
Attackers could steal credentials, configuration data, or alter application files if a user is tricked into clicking a link.
Conditions required to exploit
User must click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities