Description
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.
Exploits (5)
nomisec
SCANNER
2 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2024-34470
nomisec
WORKING POC
1 stars
by osvaldotenorio · poc
https://github.com/osvaldotenorio/CVE-2024-34470
Nuclei Templates (1)
HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion
HIGHVERIFIEDby topscoder
FOFA:
mailinspector/public
Scores
CVSS v3
8.6
EPSS
0.9364
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-29
Status
published
Products (1)
hsclabs/mailinspector
5.2.17-3 - 5.2.19
Published
May 06, 2024
Tracked Since
Feb 18, 2026