CVE-2024-6433: Local File Inclusion in stitionai/devika
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request to the application with a malicious snapshotpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6433?
CVE-2024-6433 has a high severity rating due to its potential to expose sensitive files through arbitrary file reading.
How do I fix CVE-2024-6433?
To fix CVE-2024-6433, validate and sanitize the user input for the snapshot_path parameter to prevent path traversal attacks.
What effect does CVE-2024-6433 have on the affected software?
CVE-2024-6433 allows attackers to exploit the zipping functionality to read arbitrary files from the system.
Who is affected by CVE-2024-6433?
CVE-2024-6433 affects users of the Stitionai Devika application that utilize the zipping feature.
Can CVE-2024-6433 be exploited remotely?
Yes, CVE-2024-6433 can be exploited remotely by sending crafted requests to the vulnerable application.