Moderate severityNVD Advisory· Published Jul 1, 2015· Updated May 6, 2026
CVE-2014-1836
CVE-2014-1836
Description
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
impresscms/impresscmsPackagist | < 1.3.6 | 1.3.6 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/pedrib/PoC/blob/master/generic/impresscms-1.3.5.txtnvdExploitWEB
- community.impresscms.org/modules/smartsection/item.phpnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-wcj4-ff9m-5r7gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-1836ghsaADVISORY
- seclists.org/fulldisclosure/2014/Feb/14nvdWEB
- github.com/ImpressCMS/impresscms/issues/914ghsaWEB
- web.archive.org/web/20200228234251/http://www.securityfocus.com/bid/65279ghsaWEB
- osvdb.org/show/osvdb/102770nvd
- www.securityfocus.com/bid/65279nvd
News mentions
0No linked articles in our index yet.