CVE-2024-48766
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 69.70%
- CWE
- CWE-698
- Published
- 2025-05-13
- Last modified
- 2026-03-13
Affected products
- NetAlertX NetAlertX
Weakness type
Related vulnerabilities
- CVE-2026-16323 — Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
- CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient...
- CVE-2026-58455 — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-2699 — EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2025-8350 — Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS