Vulnerability Details CVE-2024-48510
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-48510
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.10.1
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.11.0
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.12.0
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.0
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.1
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.2
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.3
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.4
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.5
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.6
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.7
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.13.8
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.14.0
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.15.0
-
cpe:2.3:a:dotnetzip.semverd_project:dotnetzip.semverd:1.16.0
-
cpe:2.3:a:mihula:prodotnetzip:1.16.0
-
cpe:2.3:a:mihula:prodotnetzip:1.17.0
-
cpe:2.3:a:mihula:prodotnetzip:1.18.0