CVE-2024-9923

MEDIUM

Teamplus Team+ Pro < 14.0.0 - Path Traversal

Title source: rule
STIX 2.1

Description

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

Scores

CVSS v3 4.9
EPSS 0.0011
EPSS Percentile 29.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-23
Status published
Products (1)
teamplus/team\+_pro 13.5.0 - 14.0.0
Published Oct 14, 2024
Tracked Since Feb 18, 2026