CVE-2015-8357: Path Traversal
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscanworker.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8357?
CVE-2015-8357 is rated as a medium severity vulnerability due to its potential impact on sensitive information disclosure and denial of service.
How do I fix CVE-2015-8357?
To fix CVE-2015-8357, upgrade the bitrix.xscan module to version 1.0.4 or later.
Who is affected by CVE-2015-8357?
CVE-2015-8357 affects remote authenticated users of the bitrix.xscan module prior to version 1.0.4.
What types of attacks can exploit CVE-2015-8357?
CVE-2015-8357 can be exploited to perform directory traversal attacks, allowing an attacker to rename files and access sensitive data.
What is the impact of exploiting CVE-2015-8357?
Exploitation of CVE-2015-8357 can lead to unauthorized file access, information disclosure, or a denial of service.