CVE-2024-32399

HIGH NUCLEI

RaidenMAILD Mail Server <4.9.4 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-32399. PoCs published by NN0b0dy. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional proof-of-concept for CVE-2024-32399, demonstrating a directory traversal vulnerability in RaidenMAILD Mail Server v4.9.4 and earlier. The PoC includes a crafted HTTP request to access sensitive files (e.g., win.ini) via the /webeditor/ component.

Description

Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

Exploits (1)

nomisec WORKING POC
by NN0b0dy · poc
https://github.com/NN0b0dy/CVE-2024-32399

The repository contains a functional proof-of-concept for CVE-2024-32399, demonstrating a directory traversal vulnerability in RaidenMAILD Mail Server v4.9.4 and earlier. The PoC includes a crafted HTTP request to access sensitive files (e.g., win.ini) via the /webeditor/ component.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: RaidenMAILD Mail Server <= 4.9.4
No auth needed
Prerequisites: Network access to the vulnerable server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

RaidenMAILD Mail Server v.4.9.4 - Path Traversal
HIGHVERIFIEDby DhiyaneshDK
Shodan: html:"RaidenMAILD"

Scores

CVSS v3 7.6
EPSS 0.0316
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Published Apr 22, 2024
Tracked Since Feb 18, 2026