CVE Vulnerabilities

CVE-2024-48766

Execution After Redirect (EAR)

Published: May 13, 2025 | Modified: May 13, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

Weakness

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

References