Unauthenticated Path Traversal Vulnerability in iDURAR v2.0.0 Allows Exposure of Sensitive Files via Download Functionality
CVE-2024-25164

7.5HIGH

Key Information:

Vendor

iDURAR

Status
Vendor
CVE Published:
5 March 2024

What is CVE-2024-25164?

A vulnerability exists in iDURAR version 2.0.0 that allows attackers without authentication to exploit the download function, potentially exposing sensitive files on the server. By manipulating the parameters, an attacker can access files outside the intended directories, leading to unauthorized data exposure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.