Sceawere
Vulnerability Detail
CVE-2026-97244UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Creator LMS Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- WPFunnels
- Product
- Creator LMS
- Attack Type
- CWE-35 Path Traversal: '.../...//'
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:36.300Z",
"pubdate": "2026-09-30T13:17:36.300Z",
"executiveSummary": "A path traversal vulnerability exists in Creator LMS versions 1.2.19 and earlier, allowing unauthorized file system access.\nThis vulnerability is classified as an Improper Limitation of a Pathname to a Restricted Directory (CWE-22), which can lead to the unauthorized disclosure or manipulation of sensitive system files.\nThe flaw affects the contributor-facing components of the LMS, potentially allowing an attacker to escape the designated web root directory.\nBy manipulating input parameters that handle file operations, an unauthenticated or low-privileged attacker can gain unauthorized read/write access to arbitrary files residing on the host server.\nSuccessful exploitation poses significant risks to data confidentiality and integrity, potentially enabling the theft of configuration files, database credentials, or application source code.\nThe vulnerability is present in the core file-handling logic of the application, necessitating strict input validation and path sanitization controls to mitigate the underlying security weakness.\nAttackers with network access to the target web interface can leverage this flaw to traverse the server's directory structure, bypassing intended access controls.",
"technicalDetails": "The vulnerability resides within the file-handling mechanisms of Creator LMS, where user-supplied input used to reference files is insufficiently validated against directory traversal sequences.\nThe root cause is the improper handling of path separators (e.g., '../', '..\\') in file path parameters, which allows the application to resolve and access resources outside the intended application directory.\nWhen a user submits a request involving file operations—such as file uploads, downloads, or inclusions—the backend application fails to sanitize the input before constructing the final file system path.\nAn attacker can exploit this by injecting traversal sequences into the affected parameters. For instance, replacing a filename or directory path with a string like '../../../../etc/passwd' enables the attacker to break out of the target directory.\nThe attack flow typically involves identifying a vulnerable endpoint that interacts with the file system. An attacker crafts an HTTP request, often using GET or POST methods, inserting traversal payloads into headers, URL parameters, or form fields.\nThe application processes these inputs and, due to the lack of canonicalization checks or jail-like chroot restrictions, interprets the path relative to the root of the file system rather than the designated application storage folder.\nIf the application runs with elevated system permissions, this vulnerability may allow an attacker to read sensitive files, overwrite application configuration files, or inject malicious code into executable paths.\nThe impact includes full server-side information disclosure, such as retrieving sensitive environmental variables, site credentials, or system logs. Furthermore, depending on the file system permissions and the nature of the operations supported by the vulnerable component, an attacker may be able to perform unauthorized file uploads, potentially leading to Remote Code Execution (RCE) via web shell deployment.\nThis vulnerability affects all Creator LMS installations up to and including version 1.2.19, and requires no specific authentication if the vulnerable file-handling endpoint is publicly reachable over the network."
}