Vulnerability Description
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squiz | Matrix | >= 5.3.0.0, <= 5.3.6.1 |
Related Weaknesses (CWE)
References
- http://devalias.net/devalias/2017/09/07/squiz-matrix-multiple-vulnerabilities/Issue TrackingThird Party Advisory
- http://devalias.net/devalias/2017/09/07/squiz-matrix-multiple-vulnerabilities/Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-14196?
CVE-2017-14196 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files o...
How severe is CVE-2017-14196?
CVE-2017-14196 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14196?
Check the references section above for vendor advisories and patch information. Affected products include: Squiz Matrix.