Impact
A path traversal vulnerability exists in dgtlmoon’s Changedetection.io (up to version 0.60.7) within the static_content function of changedetectionio/flask_app.py for the visual_selector_data component. By manipulating the filename argument, an attacker can cause the web application to resolve to a directory outside the intended static file location, potentially allowing read or modification of arbitrary files on the host. This is a classic CWE‑22 weakness and can compromise confidentiality and integrity of data stored on the system.
Affected Systems
All installations of dgtlmoon:changedetection.io that are running version 0.60.7 or earlier are affected. No other vendors or products are listed. The vendor was contacted but did not respond, leaving the vulnerability unpatched in those deployments.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. According to the description, the attack can be launched remotely, although the exact authentication requirements are not specified, so the likelihood of exploitation may increase if the endpoint is publicly reachable. An attacker could retrieve sensitive configuration files or other assets, leading to a compromise of the server’s confidentiality and availability.
OpenCVE Enrichment