CVE-2024-57549: Path Traversal
Published Jan 27, 2025
·Updated
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
Affected Software
1 affected component
CmSimple CMSimple
Event History
Jan 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57549?
CVE-2024-57549 has been classified as a medium severity vulnerability due to its impact on sensitive information disclosure.
2
How do I fix CVE-2024-57549?
To fix CVE-2024-57549, users should upgrade to the latest version of CMSimple that addresses this vulnerability.
3
What type of vulnerability is CVE-2024-57549?
CVE-2024-57549 is a sensitive information disclosure vulnerability that allows unauthorized access to CMS source code.
4
Who is affected by CVE-2024-57549?
CMSimple users running version 5.16 are affected by CVE-2024-57549.
5
What causes CVE-2024-57549?
CVE-2024-57549 is caused by improper handling of file names in GET requests, enabling users to manipulate parameters to access source code.