Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.
History

Thu, 04 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:abantecart:abantecart:1.4.2:*:*:*:*:*:*:*

Thu, 04 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Abantecart
Abantecart abantecart
Vendors & Products Abantecart
Abantecart abantecart

Tue, 26 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Description Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-26T00:00:00.000Z

Updated: 2025-09-04T14:33:41.434Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50971

cve-icon Vulnrichment

Updated: 2025-09-04T14:33:02.477Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-26T20:15:40.313

Modified: 2025-09-04T18:35:02.870

Link: CVE-2025-50971

cve-icon Redhat

No data.