Project

General

Profile

Actions

Bug #16947

closed
JP JP

Potential Local File Include vulnerability via Dashboard widget sequence data

Bug #16947: Potential Local File Include vulnerability via Dashboard widget sequence data

Added by Jim Pingle 2 months ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
Dashboard
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.07
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

The Dashboard widget layout data (sequence) is not validated when making changes to widgets or when displaying widget data.

If a user can write an arbitrary file on the firewall (e.g. /tmp/test.widget.php), they could store a widget sequence value including a widget name that traverses the path to that file (e.g. ../../../../../../../../../../../tmp/test)

The Dashboard will read that PHP file and execute it as if it were a Dashboard widget.


Files

16947.patch (4.52 KB) 16947.patch Jim Pingle, 07/13/2026 07:40 PM
16947-v2.patch (4.63 KB) 16947-v2.patch Jim Pingle, 07/14/2026 05:35 PM

Related issues 1 (1 open0 closed)

Related to Todo #16950: Add upgrade code to normalize widget sequence dataNew

Actions
Actions

Also available in: Atom