{"id":"GHSA-rvmg-xc29-rvxf","summary":"Luracast Restler directory traversal vulnerability","details":"Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.","aliases":["CVE-2017-15363"],"modified":"2025-04-23T02:57:32.310457Z","published":"2022-05-13T01:10:42Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-04-23T02:22:51Z","nvd_published_at":"2017-10-15T19:29:00Z","cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15363"},{"type":"WEB","url":"https://extensions.typo3.org/extension/restler"},{"type":"PACKAGE","url":"https://github.com/AOEpeople/TYPO3_Restler"},{"type":"WEB","url":"https://github.com/AOEpeople/TYPO3_Restler/releases/tag/1.7.1"}],"affected":[{"package":{"name":"aoe/restler","ecosystem":"Packagist","purl":"pkg:composer/aoe/restler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.1"}]}],"versions":["0.10.0","0.10.1","0.10.2","0.7.0","0.8.0","0.9.0","1.0.0","1.1.0","1.1.1","1.1.10","1.1.11","1.1.12","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2.10","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.18","1.2.19","1.2.20","1.2.21","1.2.3","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.3","1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.6.0","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rvmg-xc29-rvxf/GHSA-rvmg-xc29-rvxf.json"}},{"package":{"name":"luracast/restler","ecosystem":"Packagist","purl":"pkg:composer/luracast/restler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.0"}]}],"versions":["3.0.0","3.0.0-RC4","3.0.0-RC5","3.0.0-RC6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rvmg-xc29-rvxf/GHSA-rvmg-xc29-rvxf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}