CVE-2023-49031

MEDIUM

Tikit eMarketing <6.8.3.0 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-49031. PoCs published by Yoshik0xF6.

AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2023-49031, an unauthenticated local file inclusion (LFI) vulnerability in Tikit eMarketing version 6.8.3.0. It includes attack vectors, proof-of-concept details, and remediation steps, but lacks functional exploit code.

Description

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint.

Exploits (1)

nomisec WRITEUP
by Yoshik0xF6 · poc
https://github.com/Yoshik0xF6/CVE-2023-49031

The repository provides a detailed technical analysis of CVE-2023-49031, an unauthenticated local file inclusion (LFI) vulnerability in Tikit eMarketing version 6.8.3.0. It includes attack vectors, proof-of-concept details, and remediation steps, but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Tikit eMarketing version 6.8.3.0
No auth needed
Prerequisites: Access to the vulnerable endpoint /DATA/Log/OpenLogFile
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 5.1
EPSS 0.0073
EPSS Percentile 49.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-98
Status published
Products (1)
oneadvanced/tikit_emarketing 6.8.3.0
Published Mar 03, 2025
Tracked Since Feb 18, 2026