CVE-2024-8941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/09/2024
Last modified:
30/09/2024

Description

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*