CVE-2015-8358 | Bitrix mpbuilder Module up to 1.0.11 bitrix.mpbuilder_step2.php work path traversal (Advisory 134766 / EDB-38975)
A vulnerability was found in Bitrix mpbuilder Module up to 1.0.11. It has been classified as critical. This affects an unknown part of the file admin/bitrix.mpbuilder_step2.php. The manipulation of the argument work with the input .. leads to path traversal.
This vulnerability is uniquely identified as CVE-2015-8358. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.