CVE-2015-8794: Path Traversal
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the alt parameter, related to contact photo handling.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8794?
CVE-2015-8794 is considered a medium severity vulnerability due to its ability to allow remote authenticated users to read arbitrary files.
How do I fix CVE-2015-8794?
To fix CVE-2015-8794, upgrade Roundcube to version 1.0.6 or 1.1.2 or higher to eliminate the vulnerability.
What type of vulnerability is CVE-2015-8794?
CVE-2015-8794 is an absolute path traversal vulnerability affecting Roundcube.
What versions of Roundcube are affected by CVE-2015-8794?
CVE-2015-8794 affects Roundcube versions up to and including 1.0.5 and specific versions 1.1.0 and 1.1.1.
Who can exploit CVE-2015-8794?
CVE-2015-8794 can be exploited by remote authenticated users who have access to the contact photo functionality.