Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add CVE-2024-4836 #10180

Merged
merged 3 commits into from
Jul 9, 2024
Merged

add CVE-2024-4836 #10180

merged 3 commits into from
Jul 9, 2024

Conversation

Kazgangap
Copy link
Contributor

I wrote it over the python script shared yesterday. Link: https://github.com/sleep46/CVE-2024-4836_Check/blob/main/CVE-2024-4836_Check.py

https://cert.pl/en/posts/2024/07/CVE-2024-4836/

CERT Polska has received a report about a vulnerability in Edito CMS software and participated in coordination of its disclosure.

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthorized user. The vulnerability has been assigned CVE-2024-4836 identifier.

The issue affects versions from 3.5 through 3.25. It was removed in releases which dates from 10th of January 2014. Higher versions are not affected. It is possible to disable access to sensitive files by using a modified configuration template provided by the vendor.

Template Validation

I've validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Additional References:

@ritikchaddha ritikchaddha self-assigned this Jul 3, 2024
@Kazgangap
Copy link
Contributor Author

@ritikchaddha Any news on the merge?

@ritikchaddha
Copy link
Contributor

Hello @Kazgangap, I apologize for the delay. The template has been updated. Can you please check if it works for you?

@ritikchaddha ritikchaddha added the Done Ready to merge label Jul 9, 2024
@DhiyaneshGeek DhiyaneshGeek merged commit 7642642 into projectdiscovery:main Jul 9, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done Ready to merge
3 participants