CVE-2024-11838

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/12/2024
Last modified:
01/10/2025

Description

External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plextrac:plextrac:*:*:*:*:*:*:*:* 1.61.3 (including) 2.8.1 (excluding)