Vulnerability Description
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://daly.wtf/cve-2024-45241-path-traversal-in-centralsquare-crywolf/
- https://github.com/d4lyw/CVE-2024-45241/
- https://www.centralsquare.com/solutions/public-safety-software/public-safety-age
FAQ
What is CVE-2024-45241?
CVE-2024-45241 is a vulnerability with a CVSS score of 7.5 (HIGH). A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory v...
How severe is CVE-2024-45241?
CVE-2024-45241 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45241?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.