PT-2024-22527 · Marimer Llc · Csla .Net

·

CVE-2024-28698

·

Published

2024-07-22

·

Updated

2024-08-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marimer LLC CSLA .Net versions prior to 8.0 Marimer LLC CSLA .Net version 5.5.4 and earlier
Description A Directory Traversal vulnerability allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. This issue enables a remote attacker to potentially access and manipulate files on the server.
Recommendations For Marimer LLC CSLA .Net versions prior to 5.5.4, update to version 5.5.4 or later to resolve the issue. For Marimer LLC CSLA .Net versions 6.x and 7.x, apply the available fix commits to resolve the issue. For Marimer LLC CSLA .Net version 8.0 and later, no action is required as these versions are not affected by this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28698
GHSA-9XHH-3M78-GVGJ

Affected Products

Csla .Net