CVE-2019-9889

In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.
References
Configurations

Configuration 1

cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*

Information

Published : 2019-03-21 04:01

Updated : 2019-03-26 02:09


NVD link : CVE-2019-9889

Mitre link : CVE-2019-9889

Products Affected
No products.
CWE