What the vulnerability does
01Description
Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2Member: from n/a through <= 250419.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2Member: from n/a through <= 250419.
Explanation of Vulnerability in Simple Terms
s2Member contains a path traversal vulnerability that allows high-privilege users to read sensitive files on the server. An attacker with administrative access can bypass directory restrictions and access files outside the intended scope. The vulnerability requires high-level privileges to exploit and does not affect file modification or system availability.
What an attacker can do
Read sensitive files outside the intended directory with administrative access.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access sensitive server files.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities