CVE-2024-8694
CVE-2024-8694 is a problematic path traversal vulnerability found in JFinalCMS. Specifically, versions up to 20240903 are affected, allowing remote attackers to access sensitive files. The vulnerability resides in the update function of the /admin/template/update file within the com.cms.controller.admin.TemplateController component.
The fileName argument manipulation can lead to attackers navigating the file system. Although the CVSS score is 3.8, indicating moderate severity, the SVRS score of 48 suggests a more elevated risk than CVSS indicates. Publicly available exploits exist, increasing the likelihood of exploitation. This vulnerability is significant because it allows unauthorized file access, potentially leading to data breaches and system compromise. Immediate patching or mitigation strategies are advised to minimize the attack surface. This can lead to sensitive data exposure.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.