A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.8913}

epss

{'score': 0.87912}


Mon, 26 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Centralsquare
Centralsquare crywolf
Weaknesses CWE-22
CPEs cpe:2.3:a:centralsquare:crywolf:*:*:*:*:*:*:*:*
Vendors & Products Centralsquare
Centralsquare crywolf
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 06:30:00 +0000

Type Values Removed Values Added
Description A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-26T15:24:47.333Z

Reserved: 2024-08-25T00:00:00

Link: CVE-2024-45241

cve-icon Vulnrichment

Updated: 2024-08-26T15:24:35.281Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-26T07:15:04.273

Modified: 2024-08-26T16:35:14.650

Link: CVE-2024-45241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.