CVE-2013-7300: Craig Drummond Cantata

Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2013-7301.

Affected products

  • Craig Drummond Cantata: up to and including 1.2.1; version 0.7.0 only; version 0.7.1 only; version 0.8.0 only; version 0.8.1 only; version 0.8.2 only; …

Published 2014-02-02. Last modified 2026-06-17.