CVE-2023-6900
rmountjoy92 DashMachine delete_file path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.
Una vulnerabilidad fue encontrada en rmountjoy92 DashMachine 0.5-4 y clasificada como crítica. Una función desconocida del archivo /settings/delete_file es afectada por este problema. La manipulación del archivo de argumentos conduce a path traversal: '../filedir'. El exploit ha sido divulgado al público y puede utilizarse. VDB-248258 es el identificador asignado a esta vulnerabilidad.
Eine kritische Schwachstelle wurde in rmountjoy92 DashMachine 0.5-4 entdeckt. Betroffen davon ist ein unbekannter Prozess der Datei /settings/delete_file. Durch Beeinflussen des Arguments file mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-16 CVE Reserved
- 2023-12-17 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2025-01-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-24: Path Traversal: '../filedir'
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.248258 | Technical Description |
URL | Date | SRC |
---|---|---|
https://treasure-blarney-085.notion.site/DashMachine-Arbitrary-File-Deletion-ab44f2fe68e843c393ae9e0c1d487676 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rmountjoy92 Search vendor "Rmountjoy92" | Dashmachine Search vendor "Rmountjoy92" for product "Dashmachine" | 0.5-4 Search vendor "Rmountjoy92" for product "Dashmachine" and version "0.5-4" | - |
Affected
|