Vulnerabilities > CVE-2024-0465 - Path Traversal: '../filedir' vulnerability in Code-Projects Employee Profile Management System 1.0

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
code-projects
CWE-24

Summary

A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-250570 is the identifier assigned to this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Code-Projects
1

Common Weakness Enumeration (CWE)