Description
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49919 | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories. |
References
History
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pluck-cms
Pluck-cms pluckcms |
|
| CPEs | cpe:2.3:a:pluck-cms:pluckcms:4.7.18:*:*:*:*:*:*:* | |
| Vendors & Products |
Pluck-cms
Pluck-cms pluckcms |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories. | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-10-01T13:21:08.955Z
Reserved: 2024-10-01T07:12:07.284Z
Link: CVE-2024-9405
Updated: 2024-10-01T13:21:03.879Z
Status : Awaiting Analysis
Published: 2024-10-01T12:15:03.893
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-9405
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD