Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerability has been fixed by EfficientIP team in version 8.4.1.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder. | |
| Title | Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM | |
| First Time appeared |
Solidserver
Solidserver solidserver Ipam |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:solidserver:solidserver_ipam:8.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidserver
Solidserver solidserver Ipam |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T12:23:15.740Z
Reserved: 2025-12-02T12:15:29.651Z
Link: CVE-2025-13879
No data.
Status : Received
Published: 2025-12-02T13:15:53.353
Modified: 2025-12-02T13:15:53.353
Link: CVE-2025-13879
No data.
OpenCVE Enrichment
No data.