CVE-2024-0416
MEDIUMDescription
A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250436.
Is your site exposed to CVE-2024-0416?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| csdeshang | dsmall |
References
Frequently Asked Questions
What is CVE-2024-0416? +
How severe is CVE-2024-0416? +
What products are affected by CVE-2024-0416? +
How do I check if I'm vulnerable to CVE-2024-0416? +
Related Vulnerabilities
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template …
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly …
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded …
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs …
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the …
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …