PT-2024-26994 · Targit · Targit Decision Suite

Published

2024-05-29

·

Updated

2024-09-27

·

CVE-2024-36427

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TARGIT Decision Suite versions prior to 24.06.19002
Description The issue allows authenticated attackers to read or write to server files via a crafted file request, potentially enabling code execution via a .xview file.
Recommendations For versions prior to 24.06.19002, update to version 24.06.19002 or later to resolve the issue. As a temporary workaround, consider restricting access to the file-serving function to minimize the risk of exploitation. Avoid using crafted file requests in the affected function until the issue is resolved.

Fix

Path traversal

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-36427

Affected Products

Targit Decision Suite