CVE-2024-57170
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 18, 2025
Updated: Apr 2, 2025
CWE ID 22
Summary
CVE-2024-57170 is a directory traversal vulnerability affecting SOPlanning 1.53.00. Authenticated attackers can exploit this issue in the "/process/upload.php" file by manipulating the "fichier_to_delete" parameter with directory traversal sequences, such as "../". This allows them to delete arbitrary files outside the intended upload directory. The consequences of this vulnerability can range from denial of service to disruption of application functionality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.