Path Traversal Vulnerability Affects Jobmonster
CVE-2024-37928
8.6HIGH
Summary
The vulnerability present in NooTheme's Jobmonster product is characterized by improper limitation of a pathname, which allows for path traversal. This flaw permits unauthorized file manipulation, enabling attackers to navigate through the directory structure beyond the intended boundaries. As a result, attackers can potentially delete or alter sensitive files, leading to severe consequences for system integrity and data security. The affected versions include those from the initial release up to 4.7.0. Addressing this vulnerability is essential to ensure the security of user data and the stable operation of the Jobmonster theme.
Affected Version(s)
Jobmonster <= 4.7.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)