Back

HIGH

IDURAR has a Path Traversal (unauthenticated user can read sensitive data)

Published Oct 4, 2024

Description

IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that the public endpoint is accessible to an unauthenticated user. The user's input is directly appended to the join statement without additional checks. This allows an attacker to send URL encoded malicious payload. The directory structure can be escaped to read system files by adding an encoded string (payload) at subpath location.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Oct 4, 2024
Updated Oct 4, 2024
Reserved Sep 30, 2024

CISA Vulnrichment

Updated Oct 4, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Oct 4, 2024
Updated Oct 4, 2024

GitHub

No data