Path Traversal Vulnerability in CodeFlock FREE DOWNLOAD MANAGER
CVE-2024-49315
8.6HIGH
Summary
A Path Traversal vulnerability exists in the CodeFlock FREE DOWNLOAD MANAGER that allows an attacker to access files and directories that are outside of the intended restricted directory. This weakness enables unauthorized users to traverse the file system and potentially gain access to sensitive information. The vulnerability affects all versions starting from an unspecified version up to 1.0.0, making it crucial for users to upgrade to secure their systems against potential exploitation.
Affected Version(s)
FREE DOWNLOAD MANAGER <= 1.0.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
stealthcopter (Patchstack Alliance)