First published: Fri Nov 27 2020(Updated: )
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftercms Crafter Cms | >=3.0.0<3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15681 is a directory traversal vulnerability in Crafter CMS Crafter Studio 3.0.1 that allows unauthenticated attackers to overwrite files and potentially achieve remote code execution (RCE).
CVE-2017-15681 has a severity score of 9.8 (Critical) based on the Common Vulnerability Scoring System (CVSS).
CVE-2017-15681 affects Crafter CMS Crafter Studio version 3.0.1.
The impact of CVE-2017-15681 is that unauthenticated attackers can overwrite files from the operating system, potentially leading to remote code execution (RCE).
To mitigate CVE-2017-15681, it is recommended to upgrade to a fixed version of Crafter CMS Crafter Studio.