CVE-2022-22836: Path Traversal

Published Jan 8, 2022
·
Updated

CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

Affected Software

40 affected components
CoreFTP Core Ftp<=1.2
CoreFTP Core Ftp=2.0-build_639
CoreFTP Core Ftp=2.0-build_640
CoreFTP Core Ftp=2.0-build_641
CoreFTP Core Ftp=2.0-build_642
CoreFTP Core Ftp=2.0-build_645
CoreFTP Core Ftp=2.0-build_647
CoreFTP Core Ftp=2.0-build_649
CoreFTP Core Ftp=2.0-build_651
CoreFTP Core Ftp=2.0-build_653
CoreFTP Core Ftp=2.0-build_655
CoreFTP Core Ftp=2.0-build_656
CoreFTP Core Ftp=2.0-build_657
CoreFTP Core Ftp=2.0-build_658
CoreFTP Core Ftp=2.0-build_659
CoreFTP Core Ftp=2.0-build_665
CoreFTP Core Ftp=2.0-build_667
CoreFTP Core Ftp=2.0-build_668
CoreFTP Core Ftp=2.0-build_671
CoreFTP Core Ftp=2.0-build_673
CoreFTP Core Ftp=2.0-build_674
CoreFTP Core Ftp=2.0-build_676
CoreFTP Core Ftp=2.0-build_677
CoreFTP Core Ftp=2.0-build_679
CoreFTP Core Ftp=2.0-build_682
CoreFTP Core Ftp=2.0-build_687
CoreFTP Core Ftp=2.0-build_689
CoreFTP Core Ftp=2.0-build_691
CoreFTP Core Ftp=2.0-build_694
CoreFTP Core Ftp=2.0-build_695
CoreFTP Core Ftp=2.0-build_697
CoreFTP Core Ftp=2.0-build_699
CoreFTP Core Ftp=2.0-build_702
CoreFTP Core Ftp=2.0-build_704
CoreFTP Core Ftp=2.0-build_705
CoreFTP Core Ftp=2.0-build_711
CoreFTP Core Ftp=2.0-build_713
CoreFTP Core Ftp=2.0-build_715
CoreFTP Core Ftp=2.0-build_719
CoreFTP Core Ftp=2.0-build_725

Event History

Jan 8, 2022
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-22836?

CVE-2022-22836 is a vulnerability in CoreFTP Server that allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.

2

How severe is CVE-2022-22836?

CVE-2022-22836 has a severity score of 6.5, which is considered medium.

3

Which software versions are affected by CVE-2022-22836?

The affected software versions include CoreFTP Server 1.2 and CoreFTP Server 2.0-build_639 to 2.0-build_725.

4

How can I fix CVE-2022-22836?

To fix CVE-2022-22836, it is recommended to update CoreFTP Server to a version that is not affected by the vulnerability.

5

Where can I find more information about CVE-2022-22836?

More information about CVE-2022-22836 can be found at the following references: [http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509](http://www.coreftp.com/forums/viewtopic.php?f=15&t=4022509) and [https://yoursecuritybores.me/coreftp-vulnerabilities/](https://yoursecuritybores.me/coreftp-vulnerabilities/)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203