PT-2024-31258 · D Zero Co. · Burgereditor Limited Edition+2

Koh You Liang

+1

·

Published

2024-10-11

·

Updated

2024-10-15

·

CVE-2024-44807

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition versions prior to 2.25.1
Description A directory listing issue allows remote attackers to obtain sensitive information by exposing a list of the uploaded files. This issue affects the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition, allowing attackers to access sensitive data.
Recommendations For versions prior to 2.25.1, update to version 2.25.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the uploaded files directory to minimize the risk of exploitation.

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-44807

Affected Products

Burgereditor
Burgereditor Limited Edition
Basercms