Junglewise Threat Intelligence

CVE-2017-5539: b2evolution directory traversal bypass in file management

CVE-2017-5539 · Severity: critical · CVSS 9.1 · Published 2017-01-23

Technologies: B2evolution. Vendors: B2evolution.

Executive brief

A security flaw in the b2evolution content management system allows unauthorized users to access or delete sensitive files on the web server. This occurs because a previous security patch was incomplete, allowing attackers to bypass restrictions and manipulate files they should not have access to. This could lead to the theft of private data, website defacement, or a total loss of site functionality.

Technical details

A path traversal vulnerability exists in b2evolution version 6.8.4-stable due to an incomplete fix for a previous traversal issue (CVE-2017-5480). An attacker can bypass the existing filter rules by using specific character sequences like '..\\/' in file paths. This allows for unauthenticated remote attackers to perform arbitrary file reads, file deletions, or verify the existence of files on the underlying filesystem. The issue was addressed in version 6.8.5-stable by improving the sanitization of user-supplied path inputs.

Affected products

  • b2evolution b2evolution 6.8.4-stable

Timeline

  • 2017-01-17: disclosed: Issue reported to vendor via GitHub and email
  • 2017-01-19: patched: Version 6.8.5-stable released with security fixes
  • 2017-01-23: advisory: NVD publication date

References

Related threats