CVE-2018-15694: Path Traversal
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15694?
CVE-2018-15694 is a vulnerability in ASUSTOR Data Master 3.1.5 and below that allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability.
How severe is CVE-2018-15694?
The severity of CVE-2018-15694 is high, with a CVSS score of 7.5.
How can an attacker exploit CVE-2018-15694?
An attacker can exploit CVE-2018-15694 by using the path traversal vulnerability to upload files to arbitrary locations, potentially leading to code execution if the "Web Server" feature is enabled.
Is there a fix for CVE-2018-15694?
Yes, to fix CVE-2018-15694, users should update to a version of ASUSTOR Data Master that is above version 3.1.5.
Where can I find more information about CVE-2018-15694?
More information about CVE-2018-15694 can be found at the following link: [https://www.tenable.com/security/research/tra-2018-22](https://www.tenable.com/security/research/tra-2018-22)