Path Traversal vulnerability on Scriptcase
Published Sep 24, 2024
7.5
HIGHCVSS 3.1
EPSS 0.60%
Description
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
Affected products
-
- Version 9.4.019StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Scriptcase | Scriptcase | unaffected |
|
- 9.4.019
-
- Version 9.4.019StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Scriptcase | Scriptcase | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vulnerability has been fixed in the latest version.
References (1)
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase | Third Party Advisory |
Change history (0)
No recorded changes yet.