What the vulnerability does
01Description
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Explanation of Vulnerability in Simple Terms
Fluent Boards Pro versions up to 2.0.11 contain a path traversal vulnerability that allows high-privilege users to cause a denial of service by disrupting site availability. The vulnerability requires administrator-level access and does not compromise data confidentiality or integrity. Sites running affected versions should update to a newer release.
What an attacker can do
An administrator can disrupt site availability through path traversal manipulation.
Potential impact on your site
Site availability can be disrupted by a malicious administrator; data theft is not possible.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities