CVE-2015-8794Path Traversal in Webmail

CWE-22Path Traversal6 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 47.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 17

Description

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Debianroundcube/roundcube_webmail< 1.1.2+dfsg.1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fv6h-3g7x-x6v7: Absolute path traversal vulnerability in program/steps/addressbook/photo2022-05-17
CVEList
CVE-2015-8794: Absolute path traversal vulnerability in program/steps/addressbook/photo2016-01-29
OSV
CVE-2015-8794: Absolute path traversal vulnerability in program/steps/addressbook/photo2016-01-29

📋Vendor Advisories

1
Debian
CVE-2015-8794: roundcube - Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in ...2015

💬Community

1
Bugzilla
CVE-2015-8794 roundcube: absolute path traversal vulnerability2016-02-02
CVE-2015-8794 — Path Traversal in Roundcube Webmail | cvebase