CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-45186

Medium Severity
30
SVRS
NA
CVSSv3
0.00162
EPSS
TAGS
In The Wild
PUBLICATION DATE2024-10-02
LAST MODIFIED2024-10-02

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-45186, is a server-side template injection (SSTI) flaw present in FileSender versions prior to 2.49. It is critical because it allows an attacker to retrieve sensitive credentials from the server, potentially leading to unauthorized access, privilege escalation, and full system compromise.
2. What are the CVSS score, severity level, and disclosure details?
The Common Vulnerability Scoring System (CVSS) score for this vulnerability is not provided in the given data. The vulnerability was published on October 2, 2024, at 00:00:00 UTC and last modified on October 2, 2024, at 14:04:49 UTC.
3. Which products, vendors, systems, and versions are affected?
The affected product is FileSender. Specifically, all versions of FileSender before version 2.49 are vulnerable to this server-side template injection flaw.
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is a server-side template injection (SSTI). This occurs when user-supplied input is insecurely processed and rendered within server-side templates, allowing an attacker to inject and execute arbitrary template directives. The primary attack vector involves manipulating input fields or parameters that are subsequently used in template rendering, enabling the retrieval of credentials.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker injecting malicious code or expressions into a template that is processed on the server-side. Through successful template injection, the attacker can execute arbitrary server-side code to access and exfiltrate sensitive data, particularly credentials. The specific method of injection would depend on how FileSender processes user-controlled data within its templates.
6. What mitigation steps and patches are available?
The primary mitigation step is to upgrade FileSender to version 2.49 or a later patched version. This update will contain the necessary fixes to address the server-side template injection vulnerability.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the installed version of FileSender. Any deployment running a version of FileSender older than 2.49 is susceptible to this vulnerability. System administrators should verify their FileSender installations and compare the version number against the known patched version.
11. What is the risk assessment and urgency level?
The risk level for CVE-2024-45186 is assessed as high. The ability to retrieve credentials via server-side template injection poses a severe threat, as it can directly lead to unauthorized access, data breaches, and compromise of the underlying system. The urgency level is critical, and immediate action is required to patch affected systems to prevent potential exploitation and credential theft.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

No affected software found for this CVE

ReferenceLink
[email protected]https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/
CWE IDCWE NameDescription
CWE-94Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.