PT-2024-41092 · Netalertxnetalertx+3 · *+1
Published
2024-09-28
·
Updated
2025-06-24
·
CVE-2024-48766
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
NetAlertX versions 24.7.18 through 24.10.12
Description:
The issue allows unauthenticated file reading due to factors related to
strpos and directory traversal, where an HTTP client can ignore a redirect. This is related to components/logs.php. The vulnerability is also associated with incorrect restriction of the path name to a directory with limited access, resulting from a lack of authentication. Exploitation of the vulnerability may allow an attacker to read arbitrary files.Recommendations:
For versions 24.7.18 through 24.10.12, update to version 24.10.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the components/logs.php file until a patch is available. Avoid using the
strpos function in conjunction with directory traversal to minimize the risk of exploitation. Restrict access to sensitive directories to prevent unauthorized file reading.Exploit
Fix
Path traversal
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
*
Netalertx