A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
https://github.com/d4lyw/CVE-2024-45241/
https://daly.wtf/cve-2024-45241-path-traversal-in-centralsquare-crywolf/