CVE-2024-42718 Details
Description
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
A path traversal vulnerability has been identified in Croogo CMS version 4.0.7. This vulnerability allows authenticated remote attackers to read arbitrary files by exploiting the 'edit-file' parameter with a crafted path. The issue arises from insufficient validation of user input, enabling attackers to traverse directories and access files outside the web root, such as the sensitive '/etc/passwd' file.
To address this vulnerability, Croogo CMS should implement stricter input validation and sanitization to prevent path traversal attacks. Access controls should be applied to restrict unauthorized users from accessing sensitive files. Additionally, web server configurations should be reviewed to ensure that critical system files are not accessible through the web server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/croogo/croogo | [email protected] | Product |
| https://github.com/jacopo1223/jacopo.github/tree/main/CVE-2024-42718 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| croogo croogo | 4.0.7 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | Initial Analysis | [email protected] |
| Dec 27, 2025 | CVE Modified | CISA-ADP |
| Dec 26, 2025 | New CVE Received | [email protected] |
| Dec 26, 2025 | CVE Modified | CISA-ADP |