Path Traversal Vulnerability in PandaXGO Product
CVE-2024-2564
Key Information:
Badges
What is CVE-2024-2564?
A critical path traversal vulnerability has been identified in PandaXGO's software, specifically within the ExportUser function located in the /apps/system/api/user.go file. This vulnerability allows an attacker to manipulate the filename argument and exploit it to execute unauthorized file access operations via the path traversal technique, such as '../filedir'. The issue can be triggered remotely, making it a significant security risk. PandaXGO versions up to 20240310 are affected, and the exploit has been publicly disclosed, underscoring the importance of prompt updates and mitigations for users of this software.
Affected Version(s)
PandaX 20240310
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
