Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.3%
exploitation probability
0.3%top 72% of all CVEs
observed exploitation
nono source reports it
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
flextype · flextypeReferences
https://github.com/flextype/flextypehttps://github.com/flextype/flextype/blob/v1.0.0-alpha.3/src/flextype/core/Entries/Entries.php#L856-L906https://github.com/flextype/flextype/issues/596https://www.vulncheck.com/advisories/flextype-cms-through-1.0.0-alpha.3-path-traversal-via-entries-rest-api