xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Xbtitfm
Xbtitfm xbtitfm
Vendors & Products Xbtitfm
Xbtitfm xbtitfm

Thu, 11 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
Title xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-11T21:42:57.485Z

Reserved: 2025-12-11T17:36:04.192Z

Link: CVE-2024-58312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T22:15:52.790

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58312

cve-icon Redhat

No data.