CVE-2026-4542: SSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal
A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4542?
CVE-2026-4542 has been classified with a high severity rating due to its potential for unauthorized file access through path traversal.
How do I fix CVE-2026-4542?
To mitigate CVE-2026-4542, it's recommended to upgrade SSCMS to the latest version beyond 4.7.0 that addresses the vulnerability.
What components are affected by CVE-2026-4542?
CVE-2026-4542 specifically affects the LayerImageController.Submit.cs file within the SSCMS 4.7.0 environment.
What kind of attack can CVE-2026-4542 facilitate?
CVE-2026-4542 can allow attackers to exploit path traversal vulnerabilities, leading to potential unauthorized file access.
Is CVE-2026-4542 specific to SSCMS 4.7.0?
Yes, CVE-2026-4542 is specifically reported for SSCMS version 4.7.0 and does not impact other versions.