File Disclosure Vulnerability in Craft CMS by Craft
CVE-2024-52292
6.5MEDIUM
What is CVE-2024-52292?
A vulnerability in Craft CMS allows attackers with write access to system notification templates to exploit the dataUrl function. By embedding malicious code, an attacker can trigger a system email that contains Base64-encoded content of sensitive files. This encoded payload can be decoded, leading to unauthorized access to arbitrary files on the server. The issue has been addressed in versions 5.4.9 and 4.12.8.