CVE-2024-11664

high

Description

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of the component TGZ File Handler. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 22b0b443acca740fc83b5544165c1f53eff3f529. It is recommended to apply a patch to fix this issue.

References

https://www.youtube.com/watch?v=FJVFtNb4_qA

https://vuldb.com/?submit.447374

https://vuldb.com/?id.285986

https://vuldb.com/?ctiid.285986

https://mega.nz/folder/ZhIiDQaI#TUJCRV-XN41L-WEVAu0sWg

https://github.com/eNMS-automation/eNMS/pull/419/commits/22b0b443acca740fc83b5544165c1f53eff3f529

https://github.com/eNMS-automation/eNMS/pull/419#issuecomment-2495640750

https://github.com/eNMS-automation/eNMS/pull/419

Details

Source: Mitre, NVD

Published: 2024-11-25

Updated: 2024-12-04

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High