CVE-2019-13915 Information
Feb 14, 2021
cve
Description
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First the attacker can write code in the editor and compile and run it approximately three times to read an arbitrary file. Second the attacker can create a symlink and then place the symlink into a ZIP archive. An unzip operation leads to read access and write access (depending on file permissions) to the symlink target. Third the attacker can import a Git repository that contains a symlink similarly leading to read and write access.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/b3log/wide/issues/355
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: