PT-2024-30880 · Unknown · Vmax Project Manager

·

CVE-2024-44014

·

Published

2024-10-05

·

Updated

2024-10-09

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vmax Project Manager versions through 1.0
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a 'Path Traversal' vulnerability. This vulnerability allows PHP Local File Inclusion and Code Injection.
Recommendations For versions through 1.0, update to a version that mitigates the risk, such as version 1.0 or later. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44014

Affected Products

Vmax Project Manager