First published: Wed Dec 16 2015(Updated: )
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitrix | <=1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8357 is rated as a medium severity vulnerability due to its potential impact on sensitive information disclosure and denial of service.
To fix CVE-2015-8357, upgrade the bitrix.xscan module to version 1.0.4 or later.
CVE-2015-8357 affects remote authenticated users of the bitrix.xscan module prior to version 1.0.4.
CVE-2015-8357 can be exploited to perform directory traversal attacks, allowing an attacker to rename files and access sensitive data.
Exploitation of CVE-2015-8357 can lead to unauthorized file access, information disclosure, or a denial of service.