PT-2026-65573 · Softaculous+1 · Speedycache – Cache+1
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SpeedyCache versions prior to 1.3.9
Description
An Arbitrary File Read issue exists due to Path Traversal, which occurs when a mismatch between CSS URL validation and path resolution allows query strings to bypass checks. Because the system does not verify if the resolved file is actually a CSS file, authenticated attackers with Administrator-level access can inject crafted
<link> tags into page content. This process allows the reading of sensitive server files, such as wp-config.php and /etc/passwd, by writing their contents into publicly accessible cache files.Recommendations
Update SpeedyCache to version 1.3.9 or later.
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Speedycache – Cache
Speedycache