Directory Traversal Vulnerability in Webgalamb by Webgalamb
CVE-2018-19512
7.2HIGH
What is CVE-2018-19512?
In Webgalamb versions up to 7.0, a vulnerability exists within the system/ajax.php file, specifically during the 'wgmfile restore' operation. This flaw allows authenticated administrator users to exploit directory traversal, leading to the unauthorized restoration of PHP files under the document root directory. As a result, an attacker could potentially execute arbitrary code within the affected system, posing significant security risks.
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
