Navigate CMS
cpe:2.3:a:naviwebs:navigate_cms:*:*:*:*:*:*:*
- <= 2.8.5
A path traversal vulnerability has been identified in Navigate CMS version 2.8.5. This vulnerability allows authenticated users to download arbitrary files by injecting directory traversal sequences into the 'id' parameter. Exploitation involves sending GET requests to 'navigate_download.php' with payloads that traverse directories, such as '../../../cfg/globals.php', to access sensitive configuration and system files outside the intended directory.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files, including configuration and system files, which could be leveraged for further attacks.
To reproduce this vulnerability, an authenticated user can send a GET request to 'navigate_download.php' with the 'id' parameter set to a path traversal payload. The server response will include the contents of the requested file, demonstrating the successful exploitation of the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.