CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2017-15681

Critical · CVSS 9.8

Crafter CMS Crafter Studio — Directory Traversal / Path Traversal leading to unauthenticated arbitrary file overwrite and RCE (CWE-22)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-22

Description

In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

Search profile — drives PoC discovery

Symbols crafter-studioorg.craftercmsdirectory traversalfile overwriteunauthenticatedpath traversalRCEcraftercms
Keywords CVE-2017-15681Crafter CMSCrafter Studiodirectory traversalpath traversalunauthenticated file overwriteRCEcrafter-studio exploitcraftercms vulnerability3.0.1
Versions: 3.0.1

Affected packages

Maven org.craftercms:crafter-studio 0 → 3.0.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z