CVE-2024-25006: Path Traversal
Published Feb 2, 2024
·Updated
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Affected Software
2 affected components
XenForo Xenforo<2.2.14
XenForo Xenforo<2.2.14
Event History
Feb 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25006?
CVE-2024-25006 has a critical severity level due to its potential for directory traversal leading to unauthorized access and file manipulation.
2
How do I fix CVE-2024-25006?
To mitigate CVE-2024-25006, upgrade to XenForo version 2.2.14 or later.
3
Who is affected by CVE-2024-25006?
CVE-2024-25006 affects authenticated users with permissions to administer styles in XenForo versions prior to 2.2.14.
4
What does CVE-2024-25006 exploit in XenForo?
CVE-2024-25006 exploits a directory traversal vulnerability that allows an authenticated user to write files via ZIP archive import.
5
When was CVE-2024-25006 disclosed?
CVE-2024-25006 was disclosed in early 2024, highlighting vulnerabilities in earlier versions of XenForo.