CVE-2024-11238 is a critical path traversal vulnerability affecting Landray EKP up to version 16.0, specifically within the delPreviewFile function. An unauthenticated attacker can remotely manipulate the directoryPath argument to traverse directories, potentially leading to unauthorized file access or modification. While the CVSS score is 5.3 (Medium), its FAUCET Risk Score is 87/100, indicating a higher practical risk. Exploit code has been publicly disclosed, and Nuclei templates exist, but there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 16.0CPE matchmatch criteria | cpe:2.3:a:landray:landray_ekp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.