Path traversal in Endpoint Manager - CVE-2024-13158
Published: January 15, 2025 / Updated: January 20, 2025
Endpoint Manager
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to input validation error when processing directory traversal sequences within the MyResolveEventHandler method. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Successful exploitation of the vulnerability may lead to privilege escalation.