CVE-2024-34523

HIGH

AChecker 1.5 - Unauthenticated Path Traversal via download.php path parameter

Title source: llm
STIX 2.1

Description

AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Scores

CVSS v3 7.5
EPSS 0.0082
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Published May 07, 2024
Tracked Since Feb 18, 2026