CVE-2024-34470

Scores

EPSS

0.936high93.6%
0%20%40%60%80%100%

Percentile: 93.6%

CVSS

8.6high3.x
0246810

CVSS Score: 8.6/10

All CVSS Scores

CVSS 3.x
8.6

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-29

Exploits

Exploit ID: CVE-2024-34470

Source: github-poc

URL: https://github.com/th3gokul/CVE-2024-34470

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: mailinspector

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:hsclabs:mailinspector:*:*:*:*:*:*:*:*",      "versionEndExcluding": "5.2.19",      "versionStartIncluding": "5.2.17-3",      "vulnerable": true...

Source: nvd

End of list