PT-2024-39294 · Xiaohe4966 · Tpmecms

Wiki

+1

·

Published

2024-09-15

·

Updated

2024-09-20

·

CVE-2024-8876

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: xiaohe4966 TpMeCMS versions 1.3.3.1 and earlier
Description: A problematic issue has been found in xiaohe4966 TpMeCMS, affecting some unknown functionality of the file "/index/ajax/lang". The manipulation of the lang argument leads to path traversal. The attack may be launched remotely.
Recommendations: For xiaohe4966 TpMeCMS versions 1.3.3.1 and earlier, upgrade to version 1.3.3.2 to address this issue. As a temporary workaround, consider restricting access to the "/index/ajax/lang" file until the upgrade is applied. Avoid manipulating the lang argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-8876

Affected Products

Tpmecms