We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-5821

Local File Inclusion (LFI) in stitionai/devika



Assigner@huntr_ai
Reserved2024-06-10
Published2024-07-03
Updated2024-08-01

Description

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.



MEDIUM: 6.2CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-284 Improper Access Control

Product status

Any version
affected

References

https://huntr.com/bounties/6b729046-b9e1-4fa2-a0c5-603745a6db6b

cve.org CVE-2024-5821

nvd.nist.gov CVE-2024-5821

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.