Record summary

CVE-2017-15363 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 1.7.1 · Fixed in 1.7.1affected
GitHub AdvisoryBefore 3.1.0 · Fixed in 3.1.0affected

Nuclei templates

1
ProjectDiscoveryHIGHLuracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File InclusionCVSS 7.5

Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 is susceptible to local file inclusion in public/examples/resources/getsource.php. This could allow remote attackers to read arbitrary files via the file parameter.

Impact

The vulnerability allows an attacker to include local files, potentially leading to unauthorized access or code execution.

Remediation

Update to the latest version of Restler and TYPO3 to fix the vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2017restlerlfiedbluracasttypo3vkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:luracast:restler:*:*:*:*:*:typo3:*:*

Source: ProjectDiscovery

References

5