PT-2024-22527 · Marimer Llc · Csla .Net

Sam Pizzey

·

Published

2024-07-22

·

Updated

2024-08-16

·

CVE-2024-28698

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marimer LLC CSLA .Net versions prior to 8.0 Marimer LLC CSLA .Net version 5.5.4 and earlier
Description A Directory Traversal vulnerability allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. This issue enables a remote attacker to potentially access and manipulate files on the server.
Recommendations For Marimer LLC CSLA .Net versions prior to 5.5.4, update to version 5.5.4 or later to resolve the issue. For Marimer LLC CSLA .Net versions 6.x and 7.x, apply the available fix commits to resolve the issue. For Marimer LLC CSLA .Net version 8.0 and later, no action is required as these versions are not affected by this issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28698
GHSA-9XHH-3M78-GVGJ

Affected Products

Csla .Net