An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pluck-cms
Pluck-cms pluckcms |
|
| CPEs | cpe:2.3:a:pluck-cms:pluckcms:4.7.18:*:*:*:*:*:*:* | |
| Vendors & Products |
Pluck-cms
Pluck-cms pluckcms |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories. | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-10-01T11:22:50.340Z
Updated: 2024-10-01T13:21:08.955Z
Reserved: 2024-10-01T07:12:07.284Z
Link: CVE-2024-9405
Updated: 2024-10-01T13:21:03.879Z
Status : Awaiting Analysis
Published: 2024-10-01T12:15:03.893
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-9405
No data.