CVE-2024-47769
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 23
CWE ID 22
Summary
CVE-2024-47769 is a vulnerability affecting IDURAR, an open-source ERP CRM accounting and invoicing software. The core of the issue lies in the corePublicRouter.js file, where a public endpoint has been identified as accessible to unauthenticated users. The vulnerability enables an attacker to send a malicious URL-encoded payload, which is directly appended to a join statement without proper checks. This security oversight can lead to the attacker accessing system files by manipulating the directory structure through the subpath location.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.