xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51909 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/xbtitfm-unauthenticated-path-traversal-in-nfogenphp | Third Party Advisory |
| https://xbtitfm.eu | Product |
Configurations
History
No history.
Information
Published : 2025-12-11 22:15
Updated : 2025-12-30 19:51
NVD link : CVE-2024-58312
Mitre link : CVE-2024-58312
CVE.ORG link : CVE-2024-58312
JSON object : View
Products Affected
xbtitfm
- xbtitfm
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
