CVE-2024-25164

HIGH

idurar 2.0.0 - Unauthenticated Path Traversal via Download Functionality

Title source: llm
STIX 2.1

Description

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

Scores

CVSS v3 7.5
EPSS 0.0087
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
idurarapp/idurar 2.0.0
Published Mar 05, 2024
Tracked Since Feb 18, 2026