Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.

Project Subscriptions

Vendors Products
Efficientip Subscribe
Solidserver Ip Address Management Subscribe
Solidserver Subscribe
Solidserver Ipam Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by EfficientIP team in version 8.4.1.


Workaround

No workaround given by the vendor.

History

Fri, 30 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Efficientip
Efficientip solidserver Ip Address Management
CPEs cpe:2.3:a:efficientip:solidserver_ip_address_management:8.2.3:*:*:*:*:*:*:*
Vendors & Products Efficientip
Efficientip solidserver Ip Address Management
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Tue, 02 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.
Title Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM
First Time appeared Solidserver
Solidserver solidserver Ipam
Weaknesses CWE-22
CPEs cpe:2.3:a:solidserver:solidserver_ipam:8.2.3:*:*:*:*:*:*:*
Vendors & Products Solidserver
Solidserver solidserver Ipam
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-12-02T16:54:08.768Z

Reserved: 2025-12-02T12:15:29.651Z

Link: CVE-2025-13879

cve-icon Vulnrichment

Updated: 2025-12-02T16:50:16.613Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T13:15:53.353

Modified: 2026-01-30T20:32:44.753

Link: CVE-2025-13879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses