CVE-2024-57186 Information

Description

In Erxes <1.6.2 an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.

Reference

https://github.com/erxes/erxes/commit/d626070a0fcd435ae29e689aca051ccfb440c2f3 https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices/

Share on: