EXPOSURES › CVE-2017-15681
CVE-2017-15681
CRITICAL
DETAIL
SourceNVD · cve
Published2020-11-27
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-15681 ↗
⚡ RCE
SHAME 50/100
rce
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CVE-2017-15681 represents a critical unauthenticated directory traversal vulnerability in Crafter CMS Crafter Studio 3.0.1 allowing OS file overwrites and RCE, indicating severe security failure.
Critical vulnerability disclosed
"In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE."
Neutral database listing
Neutral NVD page
Neutral NVD page
Neutral class action site
Neutral breach results site
Neutral CISA advisory page
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.