PT-2024-13454 · Ifair · Ifair
Published
2024-01-02
·
Updated
2024-09-06
·
CVE-2023-47473
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iFair versions 23.8 ad0 and before
Description
The issue allows an attacker to obtain sensitive information via a crafted script. This is a Directory Traversal vulnerability, which means an attacker can access files and directories that are not intended to be publicly accessible.
Recommendations
For versions 23.8 ad0 and before, update to a version later than 23.8 ad0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and directories to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ifair