Path Traversal Vulnerability Affects Jobmonster
CVE-2024-37928
What is CVE-2024-37928?
The vulnerability present in NooTheme's Jobmonster product is characterized by improper limitation of a pathname, which allows for path traversal. This flaw permits unauthorized file manipulation, enabling attackers to navigate through the directory structure beyond the intended boundaries. As a result, attackers can potentially delete or alter sensitive files, leading to severe consequences for system integrity and data security. The affected versions include those from the initial release up to 4.7.0. Addressing this vulnerability is essential to ensure the security of user data and the stable operation of the Jobmonster theme.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jobmonster <= 4.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved