CVE-2024-57170

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 18, 2025
Updated: Apr 2, 2025
CWE ID 22

Summary

CVE-2024-57170 is a directory traversal vulnerability affecting SOPlanning 1.53.00. Authenticated attackers can exploit this issue in the "/process/upload.php" file by manipulating the "fichier_to_delete" parameter with directory traversal sequences, such as "../". This allows them to delete arbitrary files outside the intended upload directory. The consequences of this vulnerability can range from denial of service to disruption of application functionality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share