CVE-2024-44373

A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.
Configurations

No configuration.

History

03 Dec 2025, 17:15

Type Values Removed Values Added
References
  • () https://gh0stmezh.wordpress.com/2024/08/25/cve-2024-44373/ -
Summary (en) A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php. (en) A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.

Information

Published : 2025-08-19 19:15

Updated : 2025-12-03 17:15


NVD link : CVE-2024-44373

Mitre link : CVE-2024-44373

CVE.ORG link : CVE-2024-44373


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')