Impact
HUBzero CMS through version 2.2.32 is vulnerable to a path traversal flaw in the project file upload process. The flaw allows an authenticated project member to supply traversal sequences in the upload parameters that cause the server to write files outside the intended project repository. If the attacker can place executable scripts or web shell components, the vulnerability could lead to remote code execution with web‑server privileges.
Affected Systems
All installations of HUBzero CMS up to and including version 2.2.32 are affected. The bug resides in the file upload handlers located in the core components and plugin connections. Users should check the vendor’s release notes for the fixed version.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating a high severity level. EPSS information is not available, but the path traversal flaw can be abused by users with legitimate project membership. Since the code runs with web‑server privileges, the potential for damaging or total compromise is significant. The issue is not listed in the CISA KEV catalog, yet the high impact warrants urgent attention.
OpenCVE Enrichment