CVE-2024-6433
Last modified
CVE-2024-6433 is a vulnerability of currently unknown severity. The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request to the application with a malicious snapshot_path parameter.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request to the application with a malicious snapshot_path parameter.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-6433?
How severe is CVE-2024-6433?
How do I fix CVE-2024-6433?
Are you affected by CVE-2024-6433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
