PT-2024-39453 · Olgu Computer Systems · E-Belediye
Published
2024-09-24
·
Updated
2024-10-14
·
CVE-2024-9142
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Olgu Computer Systems e-Belediye versions prior to 2.0.642
Description
The issue allows external control of file name or path due to incorrect permission assignment for critical resources, enabling manipulation of web input to file system calls. This can lead to remote exploitation. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations
For versions prior to 2.0.642, upgrade to version 2.0.642 or later to mitigate the risk of remote exploitation. As a temporary workaround, consider restricting access to critical file system resources to minimize the risk of exploitation. Avoid using vulnerable functions that allow file inclusion until the issue is resolved.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E-Belediye