Textpattern
cpe:2.3:a:textpattern:textpattern:*:*:*:*:*:*:*
- <= 4.9.1
A path traversal vulnerability has been identified in Textpattern versions prior to 4.9.1. The issue arises in the XML-RPC Handler, specifically within the mt_uploadImage function of the rpc/TXP_RPCServer.php file. This vulnerability allows for remote exploitation by manipulating the file.name argument.
Exploitation of this vulnerability allows for path traversal, which could lead to unauthorized file access or manipulation on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.