{"id":"GHSA-wcj4-ff9m-5r7g","summary":"ImpressCMS Path Traversal to Arbitrary File Delete","details":"Absolute path traversal vulnerability in `htdocs/libraries/image-editor/image-edit.php` in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the `image_path` parameter in a cancel action.","aliases":["CVE-2014-1836"],"modified":"2023-11-08T03:57:35.126843Z","published":"2022-05-17T04:12:03Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-08-16T23:13:10Z","nvd_published_at":"2015-07-01T14:59:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1836"},{"type":"WEB","url":"https://github.com/ImpressCMS/impresscms/issues/914"},{"type":"WEB","url":"https://github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txt"},{"type":"WEB","url":"https://web.archive.org/web/20200228234251/http://www.securityfocus.com/bid/65279"},{"type":"WEB","url":"http://community.impresscms.org/modules/smartsection/item.php?itemid=675"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2014/Feb/14"}],"affected":[{"package":{"name":"impresscms/impresscms","ecosystem":"Packagist","purl":"pkg:composer/impresscms/impresscms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcj4-ff9m-5r7g/GHSA-wcj4-ff9m-5r7g.json"}}],"schema_version":"1.9.0"}