vendor:
Navigate CMS
by:
Gus Ralph
5.3
CVSS
MEDIUM
Authenticated Directory Traversal
22
CWE
Product Name: Navigate CMS
Affected Version From: 2.8.7
Affected Version To: 2.8.7
Patch Exists: NO
Related CWE: CVE-2020-13795
CPE: 2.8.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2020
Navigate CMS 2.8.7 – Authenticated Directory Traversal
A malicious user can abuse the authenticated templates functionality to traverse out of the templates directory to read and write to any file on the webserver as www-data.
Mitigation:
Ensure that the application is not vulnerable to directory traversal attacks by validating user input and restricting access to sensitive files.