CVE-2024-46446

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mecha-cms:mecha:3.0.0:*:*:*:*:*:*:*

History

11 Oct 2024, 13:04

Type Values Removed Values Added
CPE cpe:2.3:a:mecha-cms:mecha:3.0.0:*:*:*:*:*:*:*
First Time Mecha-cms mecha
Mecha-cms
References () http://mecha-cmscom.com - () http://mecha-cmscom.com - Broken Link
References () https://github.com/Sp1d3rL1/Mecha-cms-Arbitrary-File-Deletion-Vulnerability - () https://github.com/Sp1d3rL1/Mecha-cms-Arbitrary-File-Deletion-Vulnerability - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 9.8
Summary
  • (es) Mecha CMS 3.0.0 es vulnerable a Directory Traversal. Un atacante puede construir cookies y URI que eludan las comprobaciones de identidad del usuario. Luego, los parámetros se pueden pasar a través del método POST, lo que da como resultado la eliminación de archivos arbitrarios o la apropiación del sitio web.

07 Oct 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-22

07 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-07 16:15

Updated : 2024-10-11 13:04


NVD link : CVE-2024-46446

Mitre link : CVE-2024-46446

CVE.ORG link : CVE-2024-46446


JSON object : View

Products Affected

mecha-cms

  • mecha
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')