Today > | 7 High | 24 Medium | 8 Low vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-34470

May 6, 2024, 4 p.m.

Product(s) Impacted

HSC Mailinspector

  • 5.2.17-3
  • 5.2.18

Description

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

Weaknesses

Date

Published: May 6, 2024, 3:15 p.m.

Last Modified: May 6, 2024, 4 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

cve@mitre.org

References

https://github.com/ cve@mitre.org