#VU106280 Path traversal in InfiniteWP Client - CVE-2024-10585
Published: March 31, 2025
InfiniteWP Client
Revmakx
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the "historyID" parameter of the ~/debug-chart/index.php file. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.