6.5 CVE-2024-8778

Path Traversal
 

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.
https://nvd.nist.gov/vuln/detail/CVE-2024-8778

Categories

CWE-36 : Absolute Path Traversal
This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
597 Absolute Path Traversal