x
btitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51909 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/xbtitfm-unauthenticated-path-traversal-in-nfogenphp | Third Party Advisory |
| https://xbtitfm.eu | Product |
Configurations
History
30 Dec 2025, 19:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Xbtitfm xbtitfm
Xbtitfm |
|
| CPE | cpe:2.3:a:xbtitfm:xbtitfm:4.1.18:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://www.exploit-db.com/exploits/51909 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/xbtitfm-unauthenticated-path-traversal-in-nfogenphp - Third Party Advisory | |
| References | () https://xbtitfm.eu - Product |
12 Dec 2025, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-11 22:15
Updated : 2025-12-30 19:51
NVD link : CVE-2024-58312
Mitre link : CVE-2024-58312
CVE.ORG link : CVE-2024-58312
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')