Showing 1 vulnerability on this page for rubedo

Signals CISA KEV Ransomware Nuclei
rubedo_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

rubedo_project rubedo Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

CWE-22Sep 11, 20181 related artifact
CVSS9.8v3.1EPSS61.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX