PT-2024-28721 · Solara · Solara
Sunrisexu
·
Published
2024-07-12
·
Updated
2025-03-10
·
CVE-2024-39903
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Solara versions prior to 1.35.1
Description
A Local File Inclusion (LFI) vulnerability was identified in Solara, which arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.
Recommendations
For versions prior to 1.35.1, update to version 1.35.1 to resolve the issue. As a temporary workaround, consider restricting access to static files to minimize the risk of exploitation. Avoid using directory traversal sequences such as '../' in URI fragments until the issue is resolved.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solara