Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Efficientip
Efficientip solidserver Ip Address Management |
|
| CPEs | cpe:2.3:a:efficientip:solidserver_ip_address_management:8.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Efficientip
Efficientip solidserver Ip Address Management |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder. | |
| Title | Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM | |
| First Time appeared |
Solidserver
Solidserver solidserver Ipam |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:solidserver:solidserver_ipam:8.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidserver
Solidserver solidserver Ipam |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-02T12:23:15.740Z
Updated: 2025-12-02T16:54:08.768Z
Reserved: 2025-12-02T12:15:29.651Z
Link: CVE-2025-13879
Updated: 2025-12-02T16:50:16.613Z
Status : Analyzed
Published: 2025-12-02T13:15:53.353
Modified: 2026-01-30T20:32:44.753
Link: CVE-2025-13879
No data.