HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2017-15684

CVSS 7.5v3.1pub. 2020-11-27upd. 2026-07-09

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Craftercms Crafter Cms

    APP
    Craftercms
    3.0.0 – 3.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2017-15681CRITICAL9.8PL ✓same product

Path Traversal w Crafter CMS Studio umożliwiający RCE bez uwierzytelnienia

CVE-2021-23267HIGH7.6same product

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows a...

CVE-2021-23264HIGH8.1same product

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, ...

CVE-2017-15685HIGH8.6same product

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is abl...

CVE-2017-15683HIGH8.6same product

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafte...