Impact
The vulnerability arises in the project_create function of Gerapy’s Project Management component, where the project_name argument is not properly sanitized. This flaw permits attackers to perform path traversal, enabling them to read or write arbitrary files on the server’s filesystem. If exploited, a malicious user could access sensitive configuration files or modify application files, potentially compromising confidentiality or integrity of the system.
Affected Systems
The issue affects the Gerapy framework, specifically versions up to and including 0.9.13. Users running any of these releases should evaluate their deployment against the discovered path traversal flaw. The vulnerability is present in the project_create endpoint exposed by the web interface.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been observed in widespread exploitation. Remote exploitation is possible via the web interface, assuming an attacker can submit a crafted project_name value. Attackers could exploit the flaw by sending specially crafted requests to the project_create route to traverse directories and access arbitrary files.
OpenCVE Enrichment