Record summary

CVE-2024-32399 has a selected CVSS score of 7.6 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListThrough 4.9.4affected

Proofs of concept

1

Repository PoCs

GitHubNN0b0dy/CVE-2024-32399Repository PoCby NN0b0dyStars: 1Not analyzed1 file

1.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHRaidenMAILD Mail Server v.4.9.4 - Path TraversalCVSS 7.6

Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

Impact

Attackers can traverse directories to obtain sensitive information from the mail server.

Remediation

Update RaidenMAILD to a version later than 4.9.4 that patches the directory traversal vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscvecve2024lfiraidenmailservervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
CPE: cpe:2.3:a:raidenmaild:raidenmaild:*:*:*:*:*:*:*:*
Shodan: html:"RaidenMAILD"

Source: ProjectDiscovery

References

3