Arbitrary file reads via working directory traversal
Published Sep 14, 2022 · Updated Aug 3, 2024
Path traversal in UniSharp Laravel Filemanager before 2.6.4 allows remote authenticated users to read arbitrary files via download requests. The download route accepts an attacker-controlled working_dir value, while Flysystem before 2.0.0 fails to detect traversal outside the storage root. A valid application session with access to the download endpoint is required, and the consequence is limited to unauthorized file reads.
Summary
What happened
Path traversal in UniSharp Laravel Filemanager before 2.6.4 allows remote authenticated users to read arbitrary files via download requests. The download route accepts an attacker-controlled working_dir value, while Flysystem before 2.0.0 fails to detect traversal outside the storage root. A valid application session with access to the download endpoint is required, and the consequence is limited to unauthorized file reads.
The record
- CVE
- CVE-2022-40734
- Published
- Sep 14, 2022
- Updated
- Aug 3, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-22, T1005
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Jun 1, 2022Exploitation reportedJune 2022 in-the-wild exploitation
- Sep 14, 2022CVE publishedPublication date reported by the CVE source.
- Aug 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Crafted working_dir traversal requestproof of concept · observed in use
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- June 2022 in-the-wild exploitationreported exploitation
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo