Vulnerability Description
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webtrees | Webtrees | 2.1.18 |
Related Weaknesses (CWE)
References
- https://cupc4k3.medium.com/cve-2024-22723-webtrees-vulnerability-uncovering-sensExploitThird Party Advisory
- https://cupc4k3.medium.com/cve-2024-22723-webtrees-vulnerability-uncovering-sensExploitThird Party Advisory
FAQ
What is CVE-2024-22723?
CVE-2024-22723 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (...
How severe is CVE-2024-22723?
CVE-2024-22723 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22723?
Check the references section above for vendor advisories and patch information. Affected products include: Webtrees Webtrees.