An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pluck-cms
Pluck-cms pluckcms |
|
CPEs | cpe:2.3:a:pluck-cms:pluckcms:4.7.18:*:*:*:*:*:*:* | |
Vendors & Products |
Pluck-cms
Pluck-cms pluckcms |
|
Metrics |
ssvc
|
Tue, 01 Oct 2024 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories. | |
Weaknesses | CWE-23 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-10-01T11:22:50.340Z
Updated: 2024-10-01T13:21:08.955Z
Reserved: 2024-10-01T07:12:07.284Z
Link: CVE-2024-9405
Vulnrichment
Updated: 2024-10-01T13:21:03.879Z
NVD
Status : Awaiting Analysis
Published: 2024-10-01T12:15:03.893
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-9405
Redhat
No data.