Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
History

Mon, 07 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Mecha-cms
Mecha-cms mecha Cms
Weaknesses CWE-22
CPEs cpe:2.3:a:mecha-cms:mecha_cms:*:*:*:*:*:*:*:*
Vendors & Products Mecha-cms
Mecha-cms mecha Cms
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Description Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-07T00:00:00

Updated: 2024-10-07T19:20:25.373Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46446

cve-icon Vulnrichment

Updated: 2024-10-07T19:15:18.697Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2024-10-07T16:15:05.620

Modified: 2024-10-07T20:35:12.693

Link: CVE-2024-46446

cve-icon Redhat

No data.