Impact
Cloud Commander before 19.20.2 contains a directory traversal flaw in its REST file‑operation and markdown endpoints that fails to perform proper path normalization. An attacker can insert traversal sequences into request payloads to read, write, move, or copy files outside the configured root directory. This can lead to information disclosure and, if the application later executes files or if the underlying file system permissions allow it, remote code execution.
Affected Systems
The vuln affects the Cloud Commander application distributed by coderaiser (cloudcmd). All installations running a version earlier than 19.20.2 are impacted. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS base score of 9.3 indicates a high severity vulnerability. EPSS data are not available, and the flaw is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests to the REST or markdown endpoints, providing path traversal sequences such as "../../etc/passwd". If the application runs with elevated permissions or if the host system allows write access to critical directories, the vulnerability could be leveraged to modify configuration files or inject executable code, leading to potential remote code execution.
OpenCVE Enrichment