Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page. This vulnerability allows an attacker to delete files stored on the server due to a lack of proper verification of user-supplied input.
History

Fri, 29 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Quick.cms
Quick.cms quick.cms
CPEs cpe:2.3:a:quick.cms:quick.cms:*:*:*:*:*:*:*:*
Vendors & Products Quick.cms
Quick.cms quick.cms
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Description Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page. This vulnerability allows an attacker to delete files stored on the server due to a lack of proper verification of user-supplied input.
Title Path traversal vulnerability in Quick.CMS
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-11-29T13:06:30.404Z

Updated: 2024-11-29T13:24:05.020Z

Reserved: 2024-11-29T10:36:42.531Z

Link: CVE-2024-11992

cve-icon Vulnrichment

Updated: 2024-11-29T13:23:56.361Z

cve-icon NVD

Status : Received

Published: 2024-11-29T13:15:05.210

Modified: 2024-11-29T13:15:05.210

Link: CVE-2024-11992

cve-icon Redhat

No data.