peter bassill · operator
$ cve CVE-2024-53586 JSON

CVE-2024-53586 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS1.87% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2025-02-06
Last modified2026-06-17

Public exploits

SourceTitleDate
exploit-dbWebFileSys 2.31.0 - Directory Path Traversal2025-04-11

References

→ the Explorer  ·  watch your stack  ·  NVD