vendor:
PivotX
by:
Tim Coen of Curesec GmbH
4
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: PivotX
Affected Version From: 2.3.11
Affected Version To: 2.3.11
Patch Exists: NO
Related CWE: n/a
CPE: a:pivotx:pivotx:2.3.11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
PivotX 2.3.11 Directory Traversal
PivotX is a CMS for blogging written in PHP. In version 2.3.11, it is vulnerable to Directory Traversal, allowing authenticated users to read and delete files outside of the PivotX directory.
Mitigation:
This issue was not fixed by the vendor.