PT-2026-94335 · Unknown · Hubzero-Cms
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HUBzero CMS versions prior to 2.2.33
Description
A path traversal issue exists in project file upload handlers. This allows authenticated project members to write arbitrary files outside the project repository by supplying traversal sequences in upload parameters. This action is performed with web server privileges and could potentially lead to code execution.
Recommendations
Update HUBzero CMS to version 2.2.33 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hubzero-Cms