GHSA-q88g-qx42-xfrh

Suggest an improvement
Source
https://github.com/advisories/GHSA-q88g-qx42-xfrh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-q88g-qx42-xfrh/GHSA-q88g-qx42-xfrh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q88g-qx42-xfrh
Aliases
Published
2021-02-18T20:51:56Z
Modified
2024-12-02T05:55:21.347112Z
Summary
Path traversal in bolt/core
Details

Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.

Database specific
{
    "nvd_published_at": "2021-02-17T21:15:00Z",
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2021-02-18T17:53:12Z"
}
References

Affected packages

Packagist / bolt/core

Package

Name
bolt/core
Purl
pkg:composer/bolt/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.13

Affected versions

1.*

1.0.0-alpha1

4.*

4.0.0-alpha3
4.0.0-beta.1
4.0.0-beta.1.1
4.0.0-beta.1.2
4.0.0-beta.1.3
4.0.0-beta.1.4
4.0.0-beta.1.5
4.0.0-beta.1.6
4.0.0-beta.1.7
4.0.0-beta.1.8
4.0.0-beta.2
4.0.0-beta.2.1
4.0.0-beta.2.2
4.0.0-beta.2.3
4.0.0-beta.2.4
4.0.0-beta.2.5
4.0.0-beta.2.6
4.0.0-beta.2.7
4.0.0-beta.2.8
4.0.0-beta.2.9
4.0.0-beta.2.10
4.0.0-beta.3
4.0.0-beta.3.1
4.0.0-beta.3.2
4.0.0-beta.3.3
4.0.0-beta.3.4
4.0.0-beta.3.5
4.0.0-beta.3.6
4.0.0-beta.3.7
4.0.0-beta.3.8
4.0.0-beta.4
4.0.0-beta.4.1
4.0.0-beta.4.2
4.0.0-beta.4.3
4.0.0-beta.4.4
4.0.0-beta.4.5
4.0.0-beta.4.6
4.0.0-beta.5
4.0.0-beta.5.1
4.0.0-beta.5.2
4.0.0-beta.5.3
4.0.0-beta.5.4
4.0.0-beta.5.5
4.0.0-beta.5.6
4.0.0-beta.5.7
4.0.0-beta.5.8
4.0.0-beta.5.9
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.0-rc.5
4.0.0-rc.6
4.0.0-rc.7
4.0.0-rc.8
4.0.0-rc.9
4.0.0-rc.10
4.0.0-rc.11
4.0.0-rc.12
4.0.0-rc.13
4.0.0-rc.14
4.0.0-rc.15
4.0.0-rc.16
4.0.0-rc.17
4.0.0-rc.18
4.0.0-rc.19
4.0.0-rc.20
4.0.0-rc.21
4.0.0-rc.22
4.0.0-rc.23
4.0.0-rc.24
4.0.0-rc.25
4.0.0-rc.26
4.0.0-rc.27
4.0.0-rc.28
4.0.0-rc.29
4.0.0-rc.31
4.0.0-rc.32
4.0.0-rc.33
4.0.0-rc.34
4.0.0-rc.35
4.0.0-rc.37
4.0.0-rc.39
4.0.0-rc.40
4.0.0-rc.41
4.0.0-rc.42
4.0.0-rc.43
4.0.0-rc.44
4.0.0
4.0.1
4.1.0
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.7.1
4.1.8
4.1.9
4.1.10
4.1.11
4.1.12