CVE-2013-7300: Craig Drummond Cantata
Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2013-7301.
Affected products
- Craig Drummond Cantata: up to and including 1.2.1; version 0.7.0 only; version 0.7.1 only; version 0.8.0 only; version 0.8.1 only; version 0.8.2 only; …
Published 2014-02-02. Last modified 2026-06-17.