What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
Explanation of Vulnerability in Simple Terms
Embed Privacy versions up to 1.12.3 contain a path traversal vulnerability that allows authenticated users to manipulate file paths and cause the site to become unavailable. An attacker with low-level access can bypass directory restrictions and trigger a denial-of-service condition. No confidentiality breach occurs, but integrity and availability are compromised.
What an attacker can do
Make the site unavailable or corrupt files by manipulating file paths.
Potential impact on your site
Site downtime or file corruption if a user account is compromised or misused.
Conditions required to exploit
Attacker must have a low-level user account on the site.
Key dates
External resources
Related vulnerabilities