Vulnerability Description
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xenforo | Xenforo | < 2.2.14 |
Related Weaknesses (CWE)
References
- https://xenforo.com/community/threads/xenforo-2-2-14-released.219044/Release Notes
- https://xenforo.com/docs/xf2/permissions/Product
- https://xenforo.com/tickets/BC37EB98/?v=5da7bd5728Issue TrackingProduct
- https://xenforo.com/community/threads/xenforo-2-2-14-released.219044/Release Notes
- https://xenforo.com/docs/xf2/permissions/Product
- https://xenforo.com/tickets/BC37EB98/?v=5da7bd5728Issue TrackingProduct
FAQ
What is CVE-2024-25006?
CVE-2024-25006 is a vulnerability with a CVSS score of 8.1 (HIGH). XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
How severe is CVE-2024-25006?
CVE-2024-25006 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-25006?
Check the references section above for vendor advisories and patch information. Affected products include: Xenforo Xenforo.