CVE-2014-1923: Path Traversal
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-1923?
CVE-2014-1923 is a vulnerability that allows remote attackers to write to arbitrary files via unspecified vectors in Koha versions before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3.
How severe is CVE-2014-1923?
CVE-2014-1923 has a severity level of 7.5, which is considered high.
Which software versions are affected by CVE-2014-1923?
Koha versions before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 are affected by CVE-2014-1923.
How can remote attackers exploit CVE-2014-1923?
Remote attackers can exploit CVE-2014-1923 to write to arbitrary files, although the exact vectors are unspecified.
Are there any references related to CVE-2014-1923?
Yes, you can find more information about CVE-2014-1923 at the following links: [Reference 1](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11661), [Reference 2](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11662), [Reference 3](http://koha-community.org/security-release-february-2014/).