CVE-2024-32399
HIGHNuclei
RaidenMAILD Mail Server v.4.9.4 - Path Traversal
Record summary
CVE-2024-32399 has a selected CVSS score of 7.6 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
raidenmaildBrowse raidenmaild / raidenmaildDefault status: unknown | CVE List | Through 4.9.4 | affected |
Proofs of concept
1Repository PoCs
GitHubNN0b0dy/CVE-2024-32399Repository PoCby NN0b0dyStars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHRaidenMAILD Mail Server v.4.9.4 - Path TraversalCVSS 7.6
Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.
Impact
Attackers can traverse directories to obtain sensitive information from the mail server.
Remediation
Update RaidenMAILD to a version later than 4.9.4 that patches the directory traversal vulnerability.
WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscvecve2024lfiraidenmailservervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
CPE: cpe:2.3:a:raidenmaild:raidenmaild:*:*:*:*:*:*:*:*
Shodan: html:"RaidenMAILD"
https://owasp.org/www-community/attacks/Path_Traversal https://github.com/NN0b0dy/CVE-2024-32399/blob/main/README.md https://github.com/NN0b0dy/c01/blob/main/01.pdf https://github.com/NN0b0dy/CVE-2024-32399 https://github.com/nomi-sec/PoC-in-GitHub
Source: ProjectDiscovery
References
3github.com
https://github.com/NN0b0dy/CVE-2024-32399/blob/main/README.md github.com
https://github.com/NN0b0dy/c01/blob/main/01.pdf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-32399