Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2023-08-11 12:24:00

funtoosh
Member
From: Münster, Germany
Registered: 2006-10-09
Posts: 153
Website

Directory Traversal vulnerability in Textpattern CMS v4.8.8

Hi there,
A client’s provider just notified me on this vulnerability: https://www.cvedetails.com/cve/CVE-2023-36220/

They classify this as HIGH … any thoughts and fixes?

Cheers,
-martin

Offline

#2 2023-08-11 13:14:52

Bloke
Developer
From: Leeds, UK
Registered: 2006-01-29
Posts: 11,085
Website GitHub

Re: Directory Traversal vulnerability in Textpattern CMS v4.8.8

Hmmm, will investigate. As far as I’m aware. this hasn’t come through our official security channel.

Thank you for the notification. Wouldn’t have spotted it otherwise.


The smd plugin menagerie — for when you need one more gribble of power from Textpattern. Bleeding-edge code available on GitHub.

Txp Builders – finely-crafted code, design and Txp

Offline

#3 2023-08-11 13:17:55

funtoosh
Member
From: Münster, Germany
Registered: 2006-10-09
Posts: 153
Website

Re: Directory Traversal vulnerability in Textpattern CMS v4.8.8

Bloke, no problem, I was quite surprised as well by the email.

Thanx, as always.

Offline

#4 2023-08-11 13:21:31

Bloke
Developer
From: Leeds, UK
Registered: 2006-01-29
Posts: 11,085
Website GitHub

Re: Directory Traversal vulnerability in Textpattern CMS v4.8.8

From that page there is also another linked issue. Not sure if this the same one (the date is a couple of months earlier). But that one looks like it’s covered by our security considerations and is probably mitigated by employing .htaccess, as we recommend. But we’ll check that one out too just in case.


The smd plugin menagerie — for when you need one more gribble of power from Textpattern. Bleeding-edge code available on GitHub.

Txp Builders – finely-crafted code, design and Txp

Offline

Board footer

Powered by FluxBB