CVE-2017-15363
Luracast Restler directory traversal vulnerability
Record summary
CVE-2017-15363 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 26, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
restlerBrowse luracast / restler | VulnCheck | Version data not supplied | |
aoe/restlerBrowse Packagist / aoe/restler | GitHub Advisory | Before 1.7.1 · Fixed in 1.7.1 | affected |
luracast/restlerBrowse Packagist / luracast/restler | GitHub Advisory | Before 3.1.0 · Fixed in 3.1.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHLuracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File InclusionCVSS 7.5
Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 is susceptible to local file inclusion in public/examples/resources/getsource.php. This could allow remote attackers to read arbitrary files via the file parameter.
Impact
The vulnerability allows an attacker to include local files, potentially leading to unauthorized access or code execution.
Remediation
Update to the latest version of Restler and TYPO3 to fix the vulnerability.
Source: ProjectDiscovery