CVE-2024-39150
MEDIUMDescription
vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.
Is your site exposed to CVE-2024-39150?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| b3log | vditor |
References
Other References
Frequently Asked Questions
What is CVE-2024-39150? +
How severe is CVE-2024-39150? +
What products are affected by CVE-2024-39150? +
How do I check if I'm vulnerable to CVE-2024-39150? +
Related Vulnerabilities
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.
A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection …