First published: Tue May 14 2024(Updated: )
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmly |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34191 is considered a high severity vulnerability due to its potential for arbitrary file deletion.
To fix CVE-2024-34191, update to the latest version of htmly that contains the patch for this vulnerability.
CVE-2024-34191 affects htmly version 2.9.6 and earlier versions.
CVE-2024-34191 allows attackers to perform arbitrary file deletion through the delete_post() function.
If you are using htmly version 2.9.6 or earlier, your system is vulnerable to CVE-2024-34191.