Impact
A vulnerable version of Ne‑Lexa php‑zip allows an attacker to manipulate the entryName parameter of the ZipFile::extractTo method in ZipFile.php to perform a directory traversal. The flaw is a classic path‑traversal flaw (CWE‑22) that can let an adversary extract files outside the intended destination, potentially exposing sensitive data or enabling further exploitation. The description explicitly states that the attack can be initiated remotely and that the exploit is now public.
Affected Systems
The affected component is Ne‑Lexa php‑zip, version 4.0.2 and earlier. Only releases up to 4.0.2 are known to be vulnerable; later revisions may have applied the fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity and the EPSS score of less than 1% shows a very low but non‑zero likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is remotely exploitable, likely through a crafted ZIP archive that an application using the library processes.
OpenCVE Enrichment