CVE-2024-34193
HIGH EXPLOITEDsmanga 3.2.7 - Path Traversal via File Parameter
Title source: llmExploitation Summary
CVE-2024-34193 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0062
EPSS Percentile
45.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
VulnCheck KEV
2025-07-21
CWE
CWE-22
Status
published
Products (1)
lkw199711/smanga
3.2.7
Published
May 20, 2024
Tracked Since
Feb 18, 2026