← Back

Rubedo Project

rubedo_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Rubedo
rubedo

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rubedo Project
1Rubedo
Nov 21, 2024
Sep 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /the...Show more
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.Show less