
24/9/2024

30/9/2024
CVE-2024-8941: Path Traversal vulnerability on Scriptcase
First published: Tue Sep 24 2024(Updated: )
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|
Scriptcase | =9.4.019 | |
Remedy
The vulnerability has been fixed in the latest version.
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2024-8941?
CVE-2024-8941 is classified as a medium severity vulnerability due to its potential to allow unauthenticated access to sensitive directory contents.
How do I fix CVE-2024-8941?
To mitigate CVE-2024-8941, update to Scriptcase version 9.4.020 or later, which addresses this path traversal vulnerability.
Who is affected by CVE-2024-8941?
CVE-2024-8941 affects users of Scriptcase version 9.4.019 who may be exposed to unauthorized directory access.
What kind of attack does CVE-2024-8941 enable?
CVE-2024-8941 enables path traversal attacks that allow remote unauthenticated users to list and read parent directories.
Is CVE-2024-8941 being actively exploited?
As of the latest reports, there have been no confirmed active exploits specifically targeting CVE-2024-8941.
- agent/title
- agent/weakness
- agent/remedy
- agent/references
- agent/description
- agent/first-publish-date
- agent/type
- agent/author
- agent/event
- collector/mitre-cve
- source/MITRE
- agent/severity
- agent/last-modified-date
- agent/softwarecombine
- agent/trending
- collector/epss-latest
- source/FIRST
- agent/epss
- agent/source
- agent/tags
- collector/nvd-api
- source/NVD
- agent/software-canonical-lookup
- agent/software-canonical-lookup-request
- vendor/scriptcase
- canonical/scriptcase
- version/scriptcase/9.4.019
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203