ChestnutCMS Directory Traversal Vulnerability in FileController

Vulnerability

A directory traversal vulnerability has been identified in ChestnutCMS versions through 1.5.0. This vulnerability resides in the FileController of the contentcore.controller, allowing attackers to access and view any directory on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized directory access, potentially allowing attackers to view sensitive files or information stored on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
3.3
exploitability
8.9
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.