An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi user account could be displayed, e.g., configuration files with information such as the database password.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi user account could be displayed, e.g., configuration files with information such as the database password. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-27T00:00:00
Updated: 2024-12-28T18:11:43.191Z
Reserved: 2024-12-02T00:00:00
Link: CVE-2024-54452

Updated: 2024-12-28T18:11:37.996Z

Status : Awaiting Analysis
Published: 2024-12-27T20:15:23.557
Modified: 2024-12-28T19:15:07.570
Link: CVE-2024-54452

No data.