First published: Thu Nov 14 2024(Updated: )
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
EyouCms | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11210 has been rated as critical.
CVE-2024-11210 affects the editFile function in the file application/admin/logic/FilemanagerLogic.php, leading to a path traversal vulnerability.
If exploited, CVE-2024-11210 can allow an attacker to perform unauthorized access to files remotely.
To fix CVE-2024-11210, you should apply the latest security patches provided by EyouCMS or restrict the activepath input.
Yes, CVE-2024-11210 can be initiated remotely.