PT-2024-33426 · Unknown · Moridrin Ssv Events

Tahu.Datar

·

Published

2024-10-20

·

Updated

2024-10-23

·

CVE-2024-49286

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moridrin SSV Events versions 3.2.7 and earlier
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a 'Path Traversal' vulnerability, which allows PHP Local File Inclusion in Moridrin SSV Events. This vulnerability can lead to unauthorized access.
Recommendations For Moridrin SSV Events versions 3.2.7 and earlier, upgrade to a newer version as soon as possible to mitigate the risk of unauthorized access. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-49286

Affected Products

Moridrin Ssv Events