Retour à la veille

CVE-2026-104478

Publié : 3 octobre 2026
Modifié : 3 octobre 2026
Lien officiel NVD
Score CVSS
7.1
HIGH

Description détaillée

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Références et Patchs