Vulnerability Description
smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lkw199711 | Smanga | 3.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/vulreport3r/cve-reports/blob/main/Smanga_has_an_arbitrary_filExploitThird Party Advisory
- https://github.com/vulreport3r/cve-reports/blob/main/Smanga_has_an_arbitrary_filExploitThird Party Advisory
FAQ
What is CVE-2024-34193?
CVE-2024-34193 is a vulnerability with a CVSS score of 7.5 (HIGH). smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.
How severe is CVE-2024-34193?
CVE-2024-34193 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-34193?
Check the references section above for vendor advisories and patch information. Affected products include: Lkw199711 Smanga.