QID 996676
Date Published: 2024-01-15
QID 996676: PHP (Composer) Security Update for forkcms/forkcms (GHSA-4x28-j85r-668q)
Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter to frontend/js.php.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4x28-j85r-668q for updates and patch information.
Vendor References
- GHSA-4x28-j85r-668q -
github.com/advisories/GHSA-4x28-j85r-668q
CVEs related to QID 996676
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4x28-j85r-668q | forkcms/forkcms |
|