nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58312 CVE-2024-58312
HIGH
xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php
Record summary
CVE-2024-58312 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
xbtitFMBrowse xbtitfm / xbtitFMDefault status: unaffected | CVE List | 4.1.18 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBxbtitFM 4.1.18 - Multiple VulnerabilitiesExploitDB exploitby h5kj23kj32io2kjNot analyzed1 file
References
4ExploitDB-51909exploit
https://www.exploit-db.com/exploits/51909 VulnCheck Advisory: xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.phpThird-party advisory
https://www.vulncheck.com/advisories/xbtitfm-unauthenticated-path-traversal-in-nfogenphp Official Vendor Homepageproduct
https://xbtitfm.eu/