CVE-2024-8752
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
Record summary
CVE-2024-8752 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List, VulnCheck | 2.15.19 | affected |
Default status: unknown | CVE List | 2.15.19 | affected |
Proofs of concept
1Repository PoCs
GitHubD3anSPGDMS/CVE-2024-8752Repository PoCby D3anSPGDMSStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHWebIQ 2.15.9 - Directory TraversalCVSS 7.5
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.
Impact
Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Windows system, potentially exposing sensitive configuration files, credentials, database files, and system information.
Remediation
Update WebIQ to a version later than 2.15.9 to address the directory traversal vulnerability.
Source: ProjectDiscovery