CVE-2022-41951
OroPlatform vulnerable to path traversal during temporary file manipulations
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.
OroPlatform es Business Application Platform (BAP) PHP diseñada para hacer que el desarrollo de aplicaciones empresariales personalizadas sea más fácil y rápido. El Path Traversal es posible en `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. Con este método, un atacante puede pasar la ruta a un archivo inexistente, lo que permitirá escribir el contenido en un archivo nuevo que estará disponible durante la ejecución del script. Esta vulnerabilidad se ha solucionado en la versión 5.0.9.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-30 CVE Reserved
- 2023-11-27 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/oroinc/platform/security/advisories/GHSA-9v3j-4j64-p937 | 2023-12-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oroinc Search vendor "Oroinc" | Oroplatform Search vendor "Oroinc" for product "Oroplatform" | < 5.0.9 Search vendor "Oroinc" for product "Oroplatform" and version " < 5.0.9" | - |
Affected
|