Description
OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2940 | OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9. |
Github GHSA |
GHSA-9v3j-4j64-p937 | OroPlatform vulnerable to path traversal during temporary file manipulations |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T12:56:38.599Z
Reserved: 2022-09-30T16:38:28.944Z
Link: CVE-2022-41951
No data.
Status : Modified
Published: 2023-11-27T21:15:07.553
Modified: 2024-11-21T07:24:08.420
Link: CVE-2022-41951
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA