CVE-2015-4632: Path Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the templatepath parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-4632?
CVE-2015-4632 is a vulnerability in Koha versions 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 that allows remote attackers to read arbitrary files through directory traversal.
How severe is CVE-2015-4632?
CVE-2015-4632 has a severity rating of 7.5 (out of 10).
How can I exploit CVE-2015-4632?
Exploiting CVE-2015-4632 requires sending specially crafted requests with a '..%2f' (dot dot encoded slash) in the template_path parameter to certain endpoints.
How do I fix CVE-2015-4632?
To fix CVE-2015-4632, it is recommended to upgrade to Koha versions 3.14.16, 3.16.12, 3.18.08, or 3.20.1, which contain the necessary security patches.
Where can I find more information about CVE-2015-4632?
More information about CVE-2015-4632 can be found at the following references: [1] [2] [3].