CVE-2024-28698 – csla
Package
Manager: nuget
Name: csla
Vulnerable Version: >=0 <5.5.4 || >=6.0.0 <8.0.0 || >=7.0.0 <8.0.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.05096 pctl0.89415
Details
CLSA Directory Traversal vulnerability Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. Fixes for this issue have been backported to the 5.x, 6.x, and 7.x branches of CSLA. CSLA version 5.5.4 contains a fix. As of time of publication, 6.x and 7.x do not have numbered versions containing the fix but do have fix commits available.
Metadata
Created: 2024-07-22T18:31:48Z
Modified: 2024-08-15T12:23:00Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-9xhh-3m78-gvgj/GHSA-9xhh-3m78-gvgj.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-9xhh-3m78-gvgj
Finding: F063
Auto approve: 1