CVE-2018-15695: Path Traversal
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15695?
CVE-2018-15695 is a vulnerability in ASUSTOR Data Master 3.1.5 and below that allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
How severe is CVE-2018-15695?
CVE-2018-15695 has a severity rating of 6.5 (high).
How can authenticated remote non-administrative users exploit CVE-2018-15695?
Authenticated remote non-administrative users can exploit CVE-2018-15695 by using a path traversal vulnerability in wallpaper.cgi to delete any file on the file system.
What versions of ASUSTOR Data Master are affected by CVE-2018-15695?
ASUSTOR Data Master 3.1.5 and below are affected by CVE-2018-15695.
Is there a fix for CVE-2018-15695?
There is currently no fix available for CVE-2018-15695. It is recommended to update to a newer version of ASUSTOR Data Master when a patch is released.