Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-44143
Summary
nopCommerce is an open-source e-commerce platform. In versions prior to release-4.60, a Path Traversal vulnerability exists that leads to arbitrary file write. An attacker can craft a malicious request to upload an avatar to the system, which may result in arbitrary file write, including overwriting existing files used by nopCommerce. The vulnerable endpoint allows user input to determine both the mime-type of the uploaded file and its content. The mime type is determined by the unverified Content-Type header, controlled by the attacker. Additionally, the file content is solely based on the multipart request without any validation.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-22 - Path Traversal
Path traversal (or directory traversal), is a vulnerability that allows malicious users to traverse the server's root directory, gaining access to arbitrary files and folders such as application code & data, back-end credentials, and sensitive operating system files. In the worst-case scenario, an attacker could potentially execute arbitrary files on the server, resulting in a denial of service attack. Such an exploit may severely impact the integrity, confidentiality, and availability of an application.
Advisory Timeline
- Published