CVE-2024-34832

CRITICAL

Cubecart < 6.5.5 - Path Traversal

Title source: rule

Description

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

Exploits (1)

nomisec WRITEUP
by julio-cfa · poc
https://github.com/julio-cfa/CVE-2024-34832

Scores

CVSS v3 9.8
EPSS 0.0830
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
cubecart/cubecart < 6.5.5
Published Jun 06, 2024
Tracked Since Feb 18, 2026