GHSA-rj56-vp9h-3frjHighCVSS 6.5
Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to...
🔗 CVE IDs covered (1)
📋 Description
Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2018-25393
- https://www.exploit-db.com/exploits/45615
- https://www.navigatecms.com
- https://www.vulncheck.com/advisories/navigate-cms-path-traversal-via-navigate-download-php
- http://master.dl.sourceforge.net/project/navigatecms/releases/navigate-2.8.5r1355.zip
- https://github.com/advisories/GHSA-rj56-vp9h-3frj