vendor:
Devika
by:
Alperen Ergel
8.1
CVSS
CRITICAL
Path Traversal
22
CWE
Product Name: Devika
Affected Version From: v1
Affected Version To: v1
Patch Exists: NO
Related CWE: CVE-2024-40422
CPE: a:devikaai:devika:v1
Platforms Tested: Windows 11 Home Edition
2024
Devika v1 – Path Traversal via ‘snapshot_path’ Parameter
The Devika v1 application is vulnerable to a path traversal exploit via the 'snapshot_path' parameter. By manipulating the parameter, an attacker can traverse directories and access sensitive files such as /etc/passwd. This vulnerability has been assigned the CVE ID CVE-2024-40422.
Mitigation:
To mitigate this vulnerability, input validation on the 'snapshot_path' parameter should be implemented to restrict access to specific directories. Additionally, access controls should be enforced to prevent unauthorized access to sensitive files.