CVE-2024-25154
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.
Affected (1)
Products: Fortra: Filecatalyst Direct
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.8.9 |
References (4)
Source: df4dee71-de3a-4139-9588-11b62fe6c0ff
Release Notes
Source: df4dee71-de3a-4139-9588-11b62fe6c0ff
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.