Impact
The vulnerability is a path traversal flaw in the plugin install/uninstall service of MineAdmin. Unsanitized identifier values are concatenated into file system paths, allowing an attacker who can supply arbitrary identifiers to read, install, or delete files outside the intended plugin area. This can lead to arbitrary execution of composer commands and potentially arbitrary code execution. The weakness is identified as directory traversal (CWE‑22).
Affected Systems
This flaw affects the MineAdmin backend management system prior to version 3.2.0‑alpha.2. The issue manifests when the app‑store plugin service processes user‑supplied identifiers without proper sanitization. Systems running any version older than the patched release are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS score is available, and the flaw is not listed in CISA KEV. Attackers can exploit the flaw remotely through the web interface by providing crafted identifier values in the plugin install/uninstall requests. Once the path traversal is successful, the attacker can read or modify any file under the application directory and trigger composer commands, leading to code execution. The vulnerability requires network access to the MineAdmin web console and does not depend on user authentication beyond access to the plugin API.
OpenCVE Enrichment
Github GHSA