CVE-2014-9261: Codologic Codoforum
Medium severity, CVSS 5.0. EPSS: 9% chance of exploitation in the next 30 days.
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
Affected products
- Codologic Codoforum: version 2.5.1 only
Published 2015-03-23. Last modified 2026-06-17.