PT-2024-38991 · Abcd2 · Abcd2

Published

2024-09-04

·

Updated

2024-09-05

·

CVE-2024-8409

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ABCD ABCD2 versions 2.2.0-beta-1 and earlier
Description: A problematic issue has been found in ABCD ABCD2, affecting an unknown part of the file /common/show image.php. The manipulation of the image argument leads to path traversal, allowing an attacker to access files outside the intended directory using '../filedir'. This issue can be exploited remotely. The exploit has been made public and may be used. The vendor was contacted about this disclosure but did not respond.
Recommendations: For versions 2.2.0-beta-1 and earlier, as a temporary workaround, consider disabling the /common/show image.php file until a patch is available. Restrict access to this file to minimize the risk of exploitation. Avoid using the image argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8409

Affected Products

Abcd2