First published: Mon May 01 2017(Updated: )
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the `craft/app/` folder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/craftcms/cms | <2.6.2976 | 2.6.2976 |
CraftCMS Craft CMS | <=2.6.2974 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8383 is considered a medium severity vulnerability due to improper file access restrictions.
To fix CVE-2017-8383, update Craft CMS to version 2.6.2976 or later.
CVE-2017-8383 allows unauthorized users to view sensitive files within the craft/app/ directory of Craft CMS.
Yes, CVE-2017-8383 affects all versions of Craft CMS before 2.6.2976.
Users and administrators of Craft CMS versions earlier than 2.6.2976 are affected by CVE-2017-8383.