Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder. | |
| Title | Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM | |
| First Time appeared |
Solidserver
Solidserver solidserver Ipam |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:solidserver:solidserver_ipam:8.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidserver
Solidserver solidserver Ipam |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-02T12:23:15.740Z
Updated: 2025-12-02T16:54:08.768Z
Reserved: 2025-12-02T12:15:29.651Z
Link: CVE-2025-13879
Updated: 2025-12-02T16:50:16.613Z
Status : Awaiting Analysis
Published: 2025-12-02T13:15:53.353
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13879
No data.
ReportizFlow