PT-2024-41141 · Mimetex+1 · Mimetex+1
Published
2024-01-01
·
Updated
2025-11-27
·
CVE-2024-40445
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
forkosh Mime Tex versions prior to 1.77
Description
A Directory Traversal vulnerability in forkosh Mime Tex allows an attacker to execute arbitrary code via a crafted file upload. This issue enables an attacker to potentially access and manipulate files outside the intended directory structure, leading to arbitrary code execution.
Recommendations
For versions prior to 1.77, update to version 1.77 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to minimize the risk of exploitation. Avoid using the vulnerable file upload feature until the issue is resolved.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Mimetex