CVE-2024-47818 is a path traversal vulnerability affecting Saltcorn, an open-source no-code database application builder. A logged-in user, regardless of their role, can exploit this flaw by sending a crafted request to the 'sync/clean_sync_dir' endpoint, leading to the deletion of arbitrary files on the server's filesystem. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and no user interaction required, resulting in high impact to availability. While no active exploitation, public exploit code, or significant community discussion has been observed, users are strongly advised to upgrade to Saltcorn version 1.0.0-beta16 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Saltcorn | Saltcorn | < 1.0.0-beta.16CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.