Vulnerability Details CVE-2024-55602
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 contains a patch for the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.1%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2024-55602
-
cpe:2.3:a:pwndoc_project:pwndoc:-
-
cpe:2.3:a:pwndoc_project:pwndoc:0.1.0
-
cpe:2.3:a:pwndoc_project:pwndoc:0.2.0
-
cpe:2.3:a:pwndoc_project:pwndoc:0.3.0
-
cpe:2.3:a:pwndoc_project:pwndoc:0.4.0
-
cpe:2.3:a:pwndoc_project:pwndoc:0.5.0
-
cpe:2.3:a:pwndoc_project:pwndoc:0.5.1
-
cpe:2.3:a:pwndoc_project:pwndoc:0.5.2
-
cpe:2.3:a:pwndoc_project:pwndoc:0.5.3