CVE-2023-5588 is a path traversal vulnerability in the Pleroma.Emoji.Pack function of the kphrx pleroma application, specifically within the lib/pleroma/emoji/pack.ex file. This flaw allows an attacker to manipulate the 'name' argument to access unauthorized directories. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low impact on confidentiality and no impact on integrity or availability. While the attack complexity is low, the exploitability is considered difficult. There is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:kpherox:pleroma:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.