PT-2026-102780 · Rochacbruno · Marmite
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Marmite through 0.4.2 contains missing authentication in the development server endpoints / marmite /content, / marmite /config, and / marmite /file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle create content and handle clone content to write files outside the project directory via directory traversal.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marmite