GHSA-wcj4-ff9m-5r7g
Dashboard / Vulnerabilities / GHSA-wcj4-ff9m-5r7g
Summary: ImpressCMS Path Traversal to Arbitrary File Delete
Details: Absolute path traversal vulnerability in `htdocs/libraries/image-editor/image-edit.php` in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the `image_path` parameter in a cancel action.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-1836, https://github.com/ImpressCMS/impresscms/issues/914, https://github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txt, https://web.archive.org/web/20200228234251/http://www.securityfocus.com/bid/65279, http://community.impresscms.org/modules/smartsection/item.php?itemid=675, http://seclists.org/fulldisclosure/2014/Feb/14
Affected packages
Package
Name: impresscms/impresscms
Purl: pkg:composer/impresscms/impresscms
Affected ranges
Type: ECOSYSTEM
Events:
