CVE-2024-32523
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
- EPSS probability
- 1.75%
- CWE
- CWE-22, CWE-98
- Published
- 2024-05-17
- Last modified
- 2026-05-11
Affected products
- EverPress Mailster
- EverPress Mailster
Weakness type
Related vulnerabilities
- CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal
- CVE-2026-64838 — ICEcoder through 8.1 Path Traversal via oldFileName Parameter
- CVE-2026-64836 — ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
- CVE-2026-9166 — LFI in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-78085 — Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-15019 — Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment
- CVE-2026-18386 — WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter
- CVE-2026-88069 — Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis