CVE Feed

    Dashboard / CVE / CVE-2024-47769

    CVE-2024-47769

    IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that the public endpoint is accessible to an unauthenticated user. The user's input is directly appended to the join statement without additional checks. This allows an attacker to send URL encoded malicious payload. The directory structure can be escaped to read system files by adding an encoded string (payload) at subpath location.

    Published:Oct 4, 2024
    Last Modified:Nov 13, 2024
    EPS:Oct 4, 2024
    EPSS Score:0.00681
    CVSS Score:7.5

    Affected Products

    Vendor
    Idurar Project
    Product
    Idurar
    Vendor
    Idurarapp
    Product
    Idurar

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High