CVE-2017-12586: Path Traversal
Published Aug 6, 2017
·Updated
SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.
Affected Software
5 affected components
Slims Akasia=8.0
Slims Akasia=8.1
Slims Akasia=8.2
Slims Akasia=8.3
Slims Akasia=8.3.1
Event History
Aug 6, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12586?
CVE-2017-12586 has a medium severity level due to its impact on file access without proper authentication.
2
How do I fix CVE-2017-12586?
To fix CVE-2017-12586, upgrade SLiMS Akasia to version 8.3.2 or later where this vulnerability has been addressed.
3
Who is affected by CVE-2017-12586?
Remote authenticated librarian users of SLiMS Akasia versions 8.0 through 8.3.1 are affected by CVE-2017-12586.
4
What type of vulnerability is CVE-2017-12586?
CVE-2017-12586 is categorized as an arbitrary file reading vulnerability due to directory traversal.
5
Can CVE-2017-12586 be exploited remotely?
Yes, CVE-2017-12586 can be exploited remotely by authenticated users taking advantage of the directory traversal flaw.