CVE-2024-33274: Path Traversal
Published Apr 30, 2024
·Updated
Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php
Affected Software
1 affected component
FME Modules customfields<2.2.7
Event History
Apr 30, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33274?
CVE-2024-33274 is a critical vulnerability due to its potential for unauthorized information disclosure.
2
How do I fix CVE-2024-33274?
To fix CVE-2024-33274, upgrade FME Modules CustomFields to version 2.2.8 or later.
3
What types of sensitive information can be exposed by CVE-2024-33274?
CVE-2024-33274 can expose sensitive information that may include user data and configuration files.
4
Who is affected by CVE-2024-33274?
Anyone using FME Modules CustomFields version 2.2.7 or earlier is affected by CVE-2024-33274.
5
How does CVE-2024-33274 exploit the system?
CVE-2024-33274 exploits directory traversal through the Custom Checkout Fields, allowing attackers to access restricted files.