An incorrect limitation of a path to a restricted directory...
Vulnerability Description
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9405
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- David Utón Amaya (m3n0sd0n4ld)
Affected Vendor
Pluck CMS
View all reports →