Record summary

CVE-2024-4388 has a selected CVSS score of 7.5 (high).

Description

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 23, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

cas

Default status: affected

CVE ListThrough 1.0.0affected

Default status: unknown

CVE ListThrough 1.1.0affected

References

2