PT-2024-41092 · Netalertxnetalertx+3 · *+1

Published

2024-09-28

·

Updated

2025-06-24

·

CVE-2024-48766

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NetAlertX versions 24.7.18 through 24.10.12
Description: The issue allows unauthenticated file reading due to factors related to strpos and directory traversal, where an HTTP client can ignore a redirect. This is related to components/logs.php. The vulnerability is also associated with incorrect restriction of the path name to a directory with limited access, resulting from a lack of authentication. Exploitation of the vulnerability may allow an attacker to read arbitrary files.
Recommendations: For versions 24.7.18 through 24.10.12, update to version 24.10.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the components/logs.php file until a patch is available. Avoid using the strpos function in conjunction with directory traversal to minimize the risk of exploitation. Restrict access to sensitive directories to prevent unauthorized file reading.

Exploit

Fix

Path traversal

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-02475
CVE-2024-48766

Affected Products

*
Netalertx