CVE-2024-11239

A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=deleteFile of the component API Interface. The manipulation of the argument folder leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?id.284674 Permissions Required VDB Entry
https://vuldb.com/?ctiid.284674 Permissions Required VDB Entry
https://vuldb.com/?submit.438784 Third Party Advisory VDB Entry
https://github.com/CoinIsMoney/TempGuide/blob/main/LL-exp-03.pdf Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:landray:landray_ekp:*:*:*:*:*:*:*:*

History

19 Nov 2024, 19:00

Type Values Removed Values Added
First Time Landray landray Ekp
Landray
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:landray:landray_ekp:*:*:*:*:*:*:*:*
References () https://github.com/CoinIsMoney/TempGuide/blob/main/LL-exp-03.pdf - () https://github.com/CoinIsMoney/TempGuide/blob/main/LL-exp-03.pdf - Exploit
References () https://vuldb.com/?id.284674 - () https://vuldb.com/?id.284674 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.438784 - () https://vuldb.com/?submit.438784 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?ctiid.284674 - () https://vuldb.com/?ctiid.284674 - Permissions Required, VDB Entry

15 Nov 2024, 14:23

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 14:15

Updated : 2024-11-19 19:00


NVD link : CVE-2024-11239

Mitre link : CVE-2024-11239


JSON object : View

Products Affected

landray

  • landray_ekp
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')