{"id":"CVE-2022-41951","summary":"OroPlatform vulnerable to path traversal during temporary file manipulations","details":"OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\\Bundle\\GaufretteBundle\\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.","aliases":["GHSA-9v3j-4j64-p937"],"modified":"2026-08-12T03:51:43.235577922Z","published":"2023-11-27T20:27:33.911Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41951.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41951.json"},{"type":"ADVISORY","url":"https://github.com/oroinc/platform/security/advisories/GHSA-9v3j-4j64-p937"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41951"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oroinc/platform","events":[{"introduced":"a0b69d8351842924c191d1572d5f9ffe467aab65"},{"last_affected":"22d4e3359fb9c9b4f2fde2eb34442af09eb86cca"},{"introduced":"02bffd6c9c5cef5a16916b4c96cd4fab109fb999"},{"last_affected":"eefc26f3bc926f5671ca4211a0d34137ca312e9b"},{"introduced":"a98b3aa020dae96d8191a0cdfa94ad009ad41a3e"},{"fixed":"69ba18f01377fcb441bdd057302d44d9d664fa71"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"4.1.0"},{"last_affected":"4.1.13"},{"introduced":"4.2.0"},{"last_affected":"4.2.10"},{"introduced":"5.0.0"},{"fixed":"5.0.9"}]}}],"versions":["5.0.8","5.0.7","5.0.6","5.0.5","5.0.4","4.2.10","5.0.3","5.0.2","4.2.9","5.0.1","5.0.0","4.2.8","4.2.7","4.2.6","4.2.4","4.1.13","4.1.12","4.2.0","4.1.9","4.1.8","4.1.7","4.1.6","4.1.2","4.1.1-rc2","4.1.1","4.1.1-rc","4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41951.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}