CVE-2024-8941

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*

History

30 Sep 2024, 19:45

Type Values Removed Values Added
First Time Scriptcase
Scriptcase scriptcase
CPE cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase - Third Party Advisory

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Path Traversal en Scriptcase versión 9.4.019, en /scriptcase/devel/compat/nm_edit_php_edit.php (en el parámetro “subpage”), que permite a usuarios remotos no autenticados eludir las restricciones previstas por SecurityManager y enumerar y/o leer un directorio principal a través de un “/...” o directamente en una ruta utilizada en el parámetro POST “field_file” por una aplicación web.

25 Sep 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2024-09-30 19:45


NVD link : CVE-2024-8941

Mitre link : CVE-2024-8941

CVE.ORG link : CVE-2024-8941


JSON object : View

Products Affected

scriptcase

  • scriptcase
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')