PT-2026-58062 · Cpan · Dbd::File
CVE-2026-15392
·
Published
2026-07-14
·
Updated
2026-09-07
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
DBD::File versions prior to 1.651
Description
The software fails to verify if a table file is a symbolic link to an untrusted location. The
complete table name() function constructs the absolute path to the table file without checking for symbolic links. Consequently, a link placed within the data directory can point to files outside the configured f dir and f dir search directories, allowing users of file-based drivers to read or write files outside the intended data directory.Recommendations
Update to version 1.651 or later.
Exploit
Fix
DoS
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dbd::File