Impact
Laranode versions prior to 1.2.1 contain a path traversal flaw in the POST /filemanager/upload-file endpoint. The flaw permits authenticated users to supply directory traversal sequences in the path parameter, enabling them to write arbitrary files outside their devoted home directory. By placing PHP code into other tenants’ web roots, an attacker can execute code within the context of those tenants.
Affected Systems
The affected product is crivion: Laranode. All installations running a version earlier than 1.2.1 are vulnerable. No specific sub‑products are referenced other than the main Laranode application.
Risk and Exploitability
The CVSS score of 8.7 signals a high‑severity vulnerability. Although no EPSS data is available, the lack of KEV listing does not diminish the risk; the flaw allows authenticated users to gain code execution on other tenants’ sites. Exploitation can occur via the file upload endpoint, requiring no special privileges beyond normal authentication. The potential impact is significant, granting attackers full control over target tenant directories and code execution rights.
OpenCVE Enrichment