CVE-2018-15540: Path Traversal
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15540?
CVE-2018-15540 is a vulnerability in Agentejo Cockpit that allows an attacker to traverse the file system to unintended locations and/or access arbitrary files.
What is the severity of CVE-2018-15540?
The severity of CVE-2018-15540 is critical with a severity value of 9.8.
How does CVE-2018-15540 affect Agentejo Cockpit?
CVE-2018-15540 allows an attacker to perform actions on files without appropriate validation, enabling them to traverse the file system and access arbitrary files.
Is there a fix for CVE-2018-15540?
Yes, it is recommended to update Agentejo Cockpit to the latest version to fix CVE-2018-15540.
Where can I find more information about CVE-2018-15540?
You can find more information about CVE-2018-15540 at the following link: http://seclists.org/fulldisclosure/2018/Oct/30