CVE-2017-8383: Medium severity craft cms vulnerability
Published May 1, 2017
·Updated
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Other sources
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<2.6.2976
2.6.2976
Craft CMS<=2.6.2974
Event History
May 1, 2017
CVE Published
via MITRE·06:08 AM
Data Sourced
via MITRE·06:08 AM
Description
May 13, 2022
Advisory Published
01:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-8383?
CVE-2017-8383 is considered a medium severity vulnerability due to improper file access restrictions.
2
How do I fix CVE-2017-8383?
To fix CVE-2017-8383, update Craft CMS to version 2.6.2976 or later.
3
What impact does CVE-2017-8383 have on Craft CMS?
CVE-2017-8383 allows unauthorized users to view sensitive files within the craft/app/ directory of Craft CMS.
4
Is CVE-2017-8383 present in earlier versions of Craft CMS?
Yes, CVE-2017-8383 affects all versions of Craft CMS before 2.6.2976.
5
Who is affected by CVE-2017-8383?
Users and administrators of Craft CMS versions earlier than 2.6.2976 are affected by CVE-2017-8383.