CVE-2024-9923

MEDIUM

Teamplus Team+ Pro < 14.0.0 - Path Traversal

Title source: rule

Description

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

Scores

CVSS v3 4.9
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-23
Status published

Affected Products (1)

teamplus/team\+_pro < 14.0.0

Timeline

Published Oct 14, 2024
Tracked Since Feb 18, 2026