{"id":"CVE-2023-27170","title":"Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.","summary":"Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"xpand-it","product":"write-back_manager","affected":["write-back_manager = 2.3.1"],"published":"2023-10-26","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:17:20.100","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-27170","references":[{"url":"https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/","label":"cve@mitre.org"},{"url":"https://ghostline.neocities.org/CVE-2023-27170/","label":"cve@mitre.org"},{"url":"https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2024-09-10T16:30:11.608199Z"},"epss":0.00874,"epssPercentile":0.5741,"ingestedAt":"2026-09-16T20:03:30.760Z","slug":"CVE-2023-27170","body":"## Overview\n\nXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.\n\n## Affected\n\n- `write-back_manager = 2.3.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":205748,"id":"CVE-2023-27170","ts":1789592771509,"field":"cvss","old":null,"new":"7.5"},{"seq":205747,"id":"CVE-2023-27170","ts":1789592771509,"field":"severity","old":"none","new":"high"}]}