PT-2024-30883 · Minhyeong Lim · Mboard

Tahu.Datar

·

Published

2024-10-02

·

Updated

2024-10-07

·

CVE-2024-44017

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MinHyeong Lim MH Board versions 1.3.2.1 and earlier
Description The issue is related to an improper limitation of a pathname to a restricted directory, also known as a 'Path Traversal' vulnerability, which allows PHP Local File Inclusion. This vulnerability enables remote attacks.
Recommendations For versions 1.3.2.1 and earlier, update to a patched version immediately to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-44017

Affected Products

Mboard