CVE-2024-11238
Landray EKP sysUiComponent.do delPreviewFile path traversal
Record summary
CVE-2024-11238 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 9, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 16.0 | affected | |
landray_ekpBrowse landray / landray_ekpDefault status: unknown | CVE List, VulnCheck | 16.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLandray EKP - Path TraversalCVSS 6.5
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Remote attackers can access arbitrary files on the server, potentially leading to information disclosure or system compromise.
Remediation
Update to the latest version that addresses this vulnerability or apply appropriate patches.
Source: ProjectDiscovery