Xerte Online Toolkits
cpe:2.3:a:apereo:xerte_online_toolkits:*:*:*:*:*:*:*
- <= 3.15
An information disclosure vulnerability has been identified in Xerte Online Toolkits versions 3.15 and earlier. This vulnerability allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. By sending a GET request to the /setup page, attackers can access the exposed root_path value in the HTML response. This path disclosure could be exploited to navigate the filesystem or target path-dependent vulnerabilities, such as relative path traversal issues in the connector.php file.
Exploitation of this vulnerability could lead to unauthorized access to sensitive system information, specifically the full server-side filesystem path of the application root. This information could be used to exploit other vulnerabilities that depend on path information, such as relative path traversal.
To reproduce this vulnerability, send a GET request to the /setup page of the Xerte Online Toolkits application. The response will include the root_path value, which reveals the full server-side filesystem path of the application root. This path can then be used to exploit path-dependent vulnerabilities, such as relative path traversal in the connector.php file.
Users are advised to update to Xerte Online Toolkits version 3.15.0 or later, and to run the upgrade.php script after updating. The latest version can be downloaded from the Xerte Community Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.