What the vulnerability does
01Description
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
What the vulnerability does
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
Explanation of Vulnerability in Simple Terms
Participants Database versions up to 2.7.8.4 contain a path traversal vulnerability that allows an attacker to cause a denial of service by making the site unresponsive or unavailable. The vulnerability requires user interaction—typically the victim must click a malicious link or visit a crafted page. The impact extends beyond the vulnerable component itself.
What an attacker can do
Make the site unresponsive or unavailable by triggering a denial of service condition.
Potential impact on your site
Your site may become temporarily unavailable or unresponsive if a visitor is tricked into clicking a malicious link.
Conditions required to exploit
No authentication required. Victim must click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities