CVE-2024-46446

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mecha-cms:mecha:3.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-07 16:15

Updated : 2024-10-11 13:04


NVD link : CVE-2024-46446

Mitre link : CVE-2024-46446

CVE.ORG link : CVE-2024-46446


JSON object : View

Products Affected

mecha-cms

  • mecha
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')