CVE-2024-44373

A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.
Configurations

No configuration.

History

20 Aug 2025, 14:40

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de path traversal en AllSky v2023.05.01_04 permite a un atacante no autenticado crear un shell web y ejecutar código remoto a través del parámetro path, content en /includes/save_file.php.

19 Aug 2025, 20:15

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

19 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 19:15

Updated : 2025-08-20 14:40


NVD link : CVE-2024-44373

Mitre link : CVE-2024-44373

CVE.ORG link : CVE-2024-44373


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')