CVE-2015-0933

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/03/2015
Last modified:
12/04/2025

Description

Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sharelatex:sharelatex:*:*:*:*:*:*:*:* 0.1.2 (including)