Record summary

CVE-2023-34843 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubrootd4ddy/CVE-2023-34843Repository PoCby rootd4ddyStars: 8Not analyzed1 file

346 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHTraggo Server - Local File InclusionCVSS 7.5

traggo/server version 0.3.0 is vulnerable to directory traversal.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the server.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscve2023cvetraggolfiservervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:traggo:traggo:0.3.0:*:*:*:*:*:*:*
Shodan: html:"traggo"
Shodan: http.html:"traggo"
FOFA: body="traggo"

Source: ProjectDiscovery

References

2