What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files css-js-files allows Path Traversal.This issue affects CSS JS Files: from n/a through <= 1.5.0.
Explanation of Vulnerability in Simple Terms
02Summary
CSS JS Files versions 1.5.0 and earlier contain a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server. An attacker with high-level admin privileges can bypass directory restrictions and access sensitive files outside the intended scope. This requires administrative access and does not affect file integrity or availability.
What an attacker can do
03Attacker Capabilities
Read arbitrary files on the server outside the intended directory.
Potential impact on your site
04Site Impact
Administrators with malicious intent or compromised admin accounts can access sensitive files like configuration files or private data.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrator privileges on the site.
Key dates
06Disclosure timeline
October 5, 2024
CVE published
April 28, 2026
Record updated