Path Traversal Vulnerability in Droip Allows File Manipulation
CVE-2024-43955
7.5HIGH
What is CVE-2024-43955?
A vulnerability in Themeum's Droip plugin, identified as an improper limitation of a pathname to a restricted directory, allows unauthorized users to manipulate files on the server. This path traversal issue enables attackers to gain access to sensitive files that should be restricted, posing a significant risk to the security integrity of the affected sites. Users of Droip versions up to 1.1.1 are particularly vulnerable, as this flaw may lead to unauthorized file download and deletion, jeopardizing user data and site functionality.
Affected Version(s)
Droip <= 1.1.1