PT-2024-30537 · Webcrack · Webcrack

Steakenthusiast

·

Published

2024-08-14

·

Updated

2024-08-19

·

CVE-2024-43373

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions webcrack versions prior to 2.14.1
Description An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module name includes a path traversal sequence with Windows path separators, an attacker can exploit this to overwrite files on the host system. This vulnerability allows an attacker to write arbitrary .js files to the host system, which can be leveraged to hijack legitimate Node.js modules to gain arbitrary code execution.
Recommendations For versions prior to 2.14.1, update to version 2.14.1 to resolve the issue. As a temporary workaround, consider disabling the unpack bundles feature and the saving feature until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using module names that include path traversal sequences with Windows path separators in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-43373
GHSA-CCQH-278P-XQ6W

Affected Products

Webcrack