CVE-2017-5480: Path Traversal
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fmselected array parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5480?
CVE-2017-5480 has a medium severity level as it allows remote authenticated users to exploit directory traversal vulnerabilities.
How does CVE-2017-5480 impact b2evolution?
CVE-2017-5480 enables authenticated users to read or delete arbitrary files, posing a significant security risk to the application.
How do I fix CVE-2017-5480?
To fix CVE-2017-5480, it is recommended to upgrade b2evolution to a version later than 6.8.3, where the vulnerability has been patched.
Who is affected by CVE-2017-5480?
CVE-2017-5480 affects any user with back-office access to b2evolution versions up to and including 6.8.3.
What are the consequences of not addressing CVE-2017-5480?
Failing to address CVE-2017-5480 could lead to unauthorized access to sensitive files, resulting in potential data breaches.