Path Traversal Vulnerability Affects Stockholm
CVE-2024-34552
8.8HIGH
Summary
The Stockholm theme by Select-Themes contains a vulnerability that allows for improper limitation of a pathname to a restricted directory, resulting in a Path Traversal exploit. This security flaw enables attackers to potentially execute arbitrary PHP files through Local File Inclusion (LFI). The issue affects versions from n/a through 9.6, exposing users to significant risks if not addressed promptly. Stakeholders are advised to review their installations and apply security patches to mitigate potential threats.
Affected Version(s)
Stockholm <= 9.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)