PT-2024-20356 · Mgt Commerce · Mgt-Commerce Cloudpanel

Muhammad Aizat

·

Published

2024-06-14

·

Updated

2024-08-21

·

CVE-2024-24320

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mgt-commerce CloudPanel versions 2.0.0 through 2.4.0
Description A Directory Traversal issue allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
Recommendations For versions 2.0.0 through 2.4.0, consider disabling the load-logfiles function until a patch is available to prevent exploitation. Restrict access to sensitive information and limit the execution of arbitrary code by implementing additional security measures. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-24320

Affected Products

Mgt-Commerce Cloudpanel