PT-2024-28721 · Solara · Solara

Sunrisexu

·

Published

2024-07-12

·

Updated

2025-03-10

·

CVE-2024-39903

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Solara versions prior to 1.35.1
Description A Local File Inclusion (LFI) vulnerability was identified in Solara, which arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.
Recommendations For versions prior to 1.35.1, update to version 1.35.1 to resolve the issue. As a temporary workaround, consider restricting access to static files to minimize the risk of exploitation. Avoid using directory traversal sequences such as '../' in URI fragments until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39903
GHSA-9794-PC4R-438W

Affected Products

Solara