Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

changedetection.io Path Traversal

GHSA-cwgg-57xj-g77r · CVE-2024-51483

Published · Modified

Description

Summary

When a WebDriver is used to fetch files source:file:///etc/passwd can be used to retrieve local system files, where the more traditional file:///etc/passwd gets blocked

Details

The root cause is the payload source:file:///etc/passwdpasses the regex here and also passes the check here where a traditional file:///etc/passwd would get blocked

PoC

CL-ChangeDetection.io Path Travsersal-311024-181039.pdf

Impact

It depends on where the webdriver is deployed but generally this is a high impact vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes