PT-2024-30537 · Webcrack · Webcrack
Steakenthusiast
·
Published
2024-08-14
·
Updated
2024-08-19
·
CVE-2024-43373
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
webcrack versions prior to 2.14.1
Description
An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module name includes a path traversal sequence with Windows path separators, an attacker can exploit this to overwrite files on the host system. This vulnerability allows an attacker to write arbitrary
.js files to the host system, which can be leveraged to hijack legitimate Node.js modules to gain arbitrary code execution.Recommendations
For versions prior to 2.14.1, update to version 2.14.1 to resolve the issue. As a temporary workaround, consider disabling the unpack bundles feature and the saving feature until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using module names that include path traversal sequences with Windows path separators in the affected API endpoint until the issue is resolved.
Exploit
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webcrack