Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-56331

Опубликовано: 20 дек. 2024
Источник: nvd
CVSS3: 6.8
EPSS Средний

Описание

Uptime Kuma is an open source, self-hosted monitoring tool. An Improper URL Handling Vulnerability allows an attacker to access sensitive local files on the server by exploiting the file:/// protocol. This vulnerability is triggered via the "real-browser" request type, which takes a screenshot of the URL provided by the attacker. By supplying local file paths, such as file:///etc/passwd, an attacker can read sensitive data from the server. This vulnerability arises because the system does not properly validate or sanitize the user input for the URL field. Specifically: 1. The URL input (<input data-v-5f5c86d7="" id="url" type="url" class="form-control" pattern="https?://.+" required="">) allows users to input arbitrary file paths, including those using the file:/// protocol, without server-side validation. 2. The server then uses the user-provided URL to make a request, passing it to a browser instance that performs the "real-browser" request, which takes a screenshot o

EPSS

Процентиль: 97%
0.41406
Средний

6.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
github
около 1 года назад

uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor

EPSS

Процентиль: 97%
0.41406
Средний

6.8 Medium

CVSS3

Дефекты

CWE-22