CVE-2022-41951 - CVE House
Back to Database
Status published High CVE-2022-41951

OroPlatform vulnerable to path traversal during temporary file manipulations

Vulnerability Description

OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in `Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName`. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41951

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

platform
Vulnerable Versions:
>= 4.1.0, <= 4.1.13, >= 4.2.0, <= 4.2.10, >= 5.0.0, < 5.0.9

Timeline

Official Publish: November 27th, 2023
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)