PT-2024-30106 · Unknown · Super Easy Enterprise Management System

Published

2024-08-15

·

Updated

2024-11-15

·

CVE-2024-42680

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Super easy enterprise management system versions 1.0.0 and earlier
Description An issue in the system allows a local attacker to obtain the server absolute path by entering a single quotation mark. This can be exploited to gain sensitive information about the server.
Recommendations For versions 1.0.0 and earlier, as a temporary workaround, consider restricting input to prevent the entry of single quotation marks until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-42680

Affected Products

Super Easy Enterprise Management System