CVE-2024-25154: Path Traversal in FileCatalyst Direct 3.8.8 and Earlier
Published Mar 13, 2024
·Updated
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.
Affected Software
2 affected components
FileCatalyst Direct<3.8.8
Fortra Filecatalyst Direct>=3.0.0<3.8.9
Remediation
Information
Upgrade FileCatalyst to version 3.8.9 or later to remediate the path traversal vulnerability.
Event History
Mar 13, 2024
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25154?
The severity of CVE-2024-25154 can be classified as high due to the potential for data leakage via improper URL validation.
2
How do I fix CVE-2024-25154?
To fix CVE-2024-25154, users should upgrade to FileCatalyst Direct version 3.8.9 or later.
3
What kind of exploit is CVE-2024-25154 associated with?
CVE-2024-25154 is associated with a path traversal exploit that can return files outside of the web root.
4
Which versions of FileCatalyst Direct are affected by CVE-2024-25154?
CVE-2024-25154 affects FileCatalyst Direct versions 3.8.8 and earlier.
5
What could be the consequence of exploiting CVE-2024-25154?
Exploiting CVE-2024-25154 may lead to unauthorized access to sensitive files, resulting in potential data leakage.