CVE-2024-56509

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Dec 27, 2024
CWE ID 22
CWE ID 200

Summary

CVE-2024-56509 is a vulnerability affecting changedetection.io, an open-source web page change detection service. The issue involves improper input validation, enabling attackers to execute local file read (LFR) or path traversal attacks. By manipulating user input to construct incorrect file paths, such as file:../../../etc/passwd or file: ///etc/passwd, attackers can bypass weak validations and gain unauthorized access to sensitive files. Although a previous patch addressed this vulnerability, it was found to be insufficient. This issue is now resolved in version 0.48.05.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share