First published: Fri Apr 28 2017(Updated: )
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cubecart Cubecart | <=6.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2117 is considered a high severity vulnerability due to its potential to expose sensitive files to an attacker with administrative rights.
To fix CVE-2017-2117, upgrade CubeCart to version 6.1.5 or later.
CVE-2017-2117 affects CubeCart installations prior to version 6.1.5.
CVE-2017-2117 is a directory traversal vulnerability.
Yes, if an attacker has administrator rights, they can exploit CVE-2017-2117 to read arbitrary files.