CVE-2024-40348

HIGH NUCLEI

Bazaar <1.4.3 - Path Traversal

Title source: llm
STIX 2.1

Description

An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

Exploits (2)

nomisec WORKING POC 32 stars
by bigb0x · poc
https://github.com/bigb0x/CVE-2024-40348
nomisec WORKING POC
by NingXin2002 · poc
https://github.com/NingXin2002/Bazaar_poc

Nuclei Templates (1)

Bazarr < 1.4.3 - Arbitrary File Read
HIGHVERIFIEDby s4e-io
FOFA: title=="Bazarr" && icon_hash="-1983413099"

Scores

CVSS v3 8.2
EPSS 0.9338
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
bazarr/bazarr < 1.4.3
Published Jul 20, 2024
Tracked Since Feb 18, 2026