Path Traversal Vulnerability in SMSA Shipping by SMSA Express
CVE-2024-49249

8.6HIGH

Key Information:

Vendor
Smsa Express
Status
Smsa Shipping
Vendor
CVE Published:
7 January 2025

Summary

A Path Traversal vulnerability exists within the SMSA Shipping application provided by SMSA Express, which allows attackers to traverse the file system and potentially access sensitive files. This vulnerability affects all versions from n/a up to 2.3, posing significant security risks if not addressed promptly.

Affected Version(s)

SMSA Shipping <= 2.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.