5.3 CVE-2024-9405

Path Traversal
 

An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.
https://nvd.nist.gov/vuln/detail/CVE-2024-9405

Categories

CWE-23 : Relative Path Traversal
This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
139 Relative Path Traversal
High
76 Manipulating Web Input to File System Calls
Very High