CVE-2024-51483
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.
- Affected products
- Changedetection.Io
- Fix
- Available
- CVSS 4.0
- 6.9 MEDIUM
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-22
- NVD status
- Deferred
- Published
- 2024-11-01
CVE-2024-51483 at NVD
1 known exploit for CVE-2024-51483
Proof-of-concept code and exploit modules indexed by Sploitus