A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
References
| Link | Resource |
|---|---|
| https://github.com/croogo/croogo | Product |
| https://github.com/jacopo1223/jacopo.github/tree/main/CVE-2024-42718 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-26 17:15
Updated : 2025-12-31 21:35
NVD link : CVE-2024-42718
Mitre link : CVE-2024-42718
CVE.ORG link : CVE-2024-42718
JSON object : View
Products Affected
croogo
- croogo
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
