CVE-2023-39026
filemage filemage Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2023-39026 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 4, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
filemageBrowse filemage / filemageDefault status: unknown | CVE List, VulnCheck | 1.10.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFileMage Gateway 1.10.9 - Local File InclusionExploitDB exploitby Bryce Raindayzz HartyNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHFileMage Gateway - Directory TraversalCVSS 7.5
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
Impact
An attacker can view, modify, or delete sensitive files on the system, potentially leading to unauthorized access, data leakage, or system compromise.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in FileMage Gateway.
Source: ProjectDiscovery