CVE-2024-56509
CVSS 3.1 Score 8.6 of 10 (high)
Details
Summary
CVE-2024-56509 is a vulnerability affecting changedetection.io, an open-source web page change detection service. The issue involves improper input validation, enabling attackers to execute local file read (LFR) or path traversal attacks. By manipulating user input to construct incorrect file paths, such as file:../../../etc/passwd or file: ///etc/passwd, attackers can bypass weak validations and gain unauthorized access to sensitive files. Although a previous patch addressed this vulnerability, it was found to be insufficient. This issue is now resolved in version 0.48.05.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- dgtlmoon changedetection.io