NA

CVE-2024-34470

Published: 06/05/2024 Updated: 06/05/2024

Vulnerability Summary

An issue exists in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an malicious user to read arbitrary files on the server.

Github Repositories

CVE-2024-34470 Description: An Unauthenticated Path Traversal vulnerability exists in the /public/loaderphp file The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server Proof of Concept O arquivo /public/loaderphp carrega os scripts javascript e css pelo parâ