← العودة للجدول
CVE-2026-104478
CVE-2026-104478 — Formwork before 2.3.13 contains a path traversal vulnerability in BackupControll
📅 2026-10-03
🟠 High 🔥 No NVD Vulnerability Web CVSS 7.1

📋 الوصف الكامل

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.

💻 الأنظمة المتأثرة

PHP

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-104478

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-104478 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←