CVE-2024-9923

CVSS v3 Score
4.9
Medium

Vulnerability Description

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

CVSS:4.9(Medium)

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifi...

CWE-232022
CVSS:4.9(Medium)

Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on ...

CWE-232022
CVSS:4.9(Medium)

Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

CWE-232022
CVSS:4.9(Medium)

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers,...

CWE-232024
CVSS:4.9(Medium)

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

CWE-232024
CVSS:4.9(Medium)

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or ...

CWE-232024