PT-2026-96715 · Dgtlmoon · Changedetection.Io
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dgtlmoon changedetection.io versions prior to 0.60.8
Description
A path traversal issue exists in the Screenshot Handler component within the
static content() function of the changedetectionio/flask app.py file. A remote attacker can exploit this by manipulating the filename argument to access files outside the intended directory. This attack is characterized by high complexity and difficult exploitability.Recommendations
Update dgtlmoon changedetection.io to a version newer than 0.60.7.
As a temporary mitigation, restrict access to the
static content() function within the Screenshot Handler component.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Changedetection.Io