CVE-2024-53586

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 6, 2025
Updated: Feb 11, 2025
CWE ID 22

Summary

CVE-2024-53586 is a newly discovered vulnerability affecting WebFileSys version 2.31.0. This issue permits attackers to execute directory traversal attacks through manipulation of the relPath parameter in crafted HTTP requests. By injecting carefully crafted payloads into this parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory. This vulnerability poses a significant risk to systems using WebFileSys and necessitates prompt patching to mitigate potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share