What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0.
Explanation of Vulnerability in Simple Terms
uListing versions up to 2.2.0 contain a path traversal vulnerability that allows authenticated administrators to read files outside the intended directory. An attacker with high-level admin privileges can access sensitive files on the server by manipulating file paths. This vulnerability requires admin-level access and does not affect file integrity or availability.
What an attacker can do
Read arbitrary files on the server outside the intended application directory.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access sensitive server files like configuration or database credentials.
Conditions required to exploit
Attacker must have high-level administrator privileges on the site.
Key dates
External resources
Related vulnerabilities