CVE-2024-25006
EUVD-2024-2236829.02.2024, 01:44
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xenforo | xenforo | 𝑥 < 2.2.14 |
𝑥
= Vulnerable software versions
References