What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.2.
Explanation of Vulnerability in Simple Terms
Energox versions 1.2 and earlier contain a path traversal vulnerability that allows authenticated users to cause a denial of service by accessing files outside the intended directory. The vulnerability requires low-level authentication and network access. An attacker can disrupt site availability by exhausting resources or triggering errors through malicious file requests.
What an attacker can do
Cause the site to become unavailable or unresponsive by accessing restricted files.
Potential impact on your site
Your site may experience downtime or performance degradation if an authenticated user exploits this flaw.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities