PT-2023-27365 · Stakater · Stakater Forecastle

Sahar Shlichove

·

Published

2023-08-13

·

Updated

2024-07-03

·

CVE-2023-40297

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stakater Forecastle versions 1.0.139 and before
Description The issue is related to a directory traversal vulnerability in the website component, allowing %5C../ directory traversal. This vulnerability is present in the Stakater Forecastle software.
Recommendations For versions 1.0.139 and before, consider restricting access to the website component to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-40297
GHSA-X8XM-WRJQ-5G54
GO-2024-2865

Affected Products

Stakater Forecastle