CVE-2024-51376: Path Traversal
Published Feb 12, 2025
·Updated
Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component.
Affected Software
1 affected component
Yeqifu carRental
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51376?
CVE-2024-51376 is classified as a critical severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2024-51376?
To fix CVE-2024-51376, ensure proper input validation and implement restrictions to prevent directory traversal in the file path handling.
3
What kind of data can be accessed through CVE-2024-51376?
CVE-2024-51376 allows attackers to access sensitive files on the server through unauthorized file downloads.
4
Which versions of yeqifu carRental are affected by CVE-2024-51376?
CVE-2024-51376 affects yeqifu carRental version 1.0.
5
How can I identify if my system is vulnerable to CVE-2024-51376?
You can identify vulnerability to CVE-2024-51376 by testing file path parameters in the download file functionality for unauthorized access.