cbcvebase.
CVE-2022-41951
published 2023-11-27

CVE-2022-41951: OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is…

PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.95%
57.5th percentile
OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.

Affected

7 ranges
VendorProductVersion rangeFixed in
oroplatform4.1.0 – 4.1.13
oroplatform4.2.0 – 4.2.10
oroplatform>= 5.0.0 < 5.0.85.0.8
oroincoroplatform< 5.0.95.0.9
oroincplatform
oroincplatform
oroincplatform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.