CVE-2023-1105: External Control of File Name or Path in flatpressblog/flatpress
Published Mar 1, 2023
·Updated
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
Affected Software
1 affected component
flatpress flatpress<2022-12-25
Remediation
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1105?
CVE-2023-1105 is considered a medium severity vulnerability due to the potential for unauthorized access to files.
2
How do I fix CVE-2023-1105?
To fix CVE-2023-1105, upgrade Flatpress to version 1.3 or later.
3
What kind of vulnerability is CVE-2023-1105?
CVE-2023-1105 is categorized as an external control of file name or path vulnerability.
4
Which versions of Flatpress are affected by CVE-2023-1105?
Flatpress versions prior to 1.3 are affected by CVE-2023-1105.
5
Can CVE-2023-1105 lead to data leakage?
Yes, CVE-2023-1105 can potentially lead to data leakage by allowing attackers to access arbitrary files on the server.