CVE-2024-57189 Information

Description

In Erxes <1.6.2 an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

Reference

https://github.com/erxes/erxes/commit/d626070a0fcd435ae29e689aca051ccfb440c2f3 https://www.sonarsource.com/blog/micro-services-major-headaches-detecting-vulnerabilities-in-erxes-microservices/

Share on: