Description
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.
Remediation
References
Related Vulnerabilities
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338)
Joomla Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2023-23755)
MySQL Other Vulnerability (CVE-2006-1518)
Python Integer Overflow or Wraparound Vulnerability (CVE-2016-9063)
TYPO3 Improper Neutralization of HTTP Headers for Scripting Syntax Vulnerability (CVE-2021-41114)