First published: Fri Jul 12 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce OpenPos allows File Manipulation.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce | <=6.4.4 | |
WooCommerce | <=6.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37932 is considered a high-severity vulnerability due to its potential for file manipulation and unauthorized access.
To fix CVE-2024-37932, update Woocommerce OpenPos to version 6.4.5 or later.
CVE-2024-37932 can allow attackers to conduct path traversal attacks, potentially leading to unauthorized file manipulation or deletion.
CVE-2024-37932 affects all versions of Woocommerce OpenPos from n/a up to and including version 6.4.4.
Exploitation of CVE-2024-37932 can occur without user authentication, making it more critical.