PT-2024-31499 · Centralsquare · Centralsquare Crywolf
D4Lyw
·
Published
2024-08-25
·
Updated
2024-08-30
·
CVE-2024-45241
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CentralSquare CryWolf (False Alarm Management) versions prior to 2024-08-09
Description
A traversal vulnerability in GeneralDocs.aspx allows unauthenticated attackers to read files outside of the working web directory via the
rpt parameter, leading to the disclosure of sensitive information. This issue enables attackers to access sensitive data without proper authentication.Recommendations
As a temporary workaround, consider restricting access to the GeneralDocs.aspx page until a patch is available.
Limit local network access to minimize the risk of exploitation.
Patch immediately and monitor for exploit attempts.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centralsquare Crywolf