A vulnerability was found in PandaXGO PandaX up to 20240310 and classified as critical. This issue affects the function ExportUser of the file /apps/system/api/user.go. The manipulation of the argument filename leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257063.
References
| Link | Resource |
|---|---|
| https://github.com/PandaXGO/PandaX/issues/6 | Issue Tracking |
| https://vuldb.com/?ctiid.257063 | Permissions Required |
| https://vuldb.com/?id.257063 | Permissions Required |
| https://github.com/PandaXGO/PandaX/issues/6 | Issue Tracking |
| https://vuldb.com/?ctiid.257063 | Permissions Required |
| https://vuldb.com/?id.257063 | Permissions Required |
Configurations
History
17 Jun 2026, 07:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pandax:pandax:*:*:*:*:*:*:*:* | |
| First Time |
Pandax pandax
Pandax |
|
| References | () https://github.com/PandaXGO/PandaX/issues/6 - Issue Tracking | |
| References | () https://vuldb.com/?ctiid.257063 - Permissions Required | |
| References | () https://vuldb.com/?id.257063 - Permissions Required |
21 Nov 2024, 09:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/PandaXGO/PandaX/issues/6 - | |
| References | () https://vuldb.com/?ctiid.257063 - | |
| References | () https://vuldb.com/?id.257063 - |
17 Mar 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-17 14:15
Updated : 2026-06-17 07:24
NVD link : CVE-2024-2564
Mitre link : CVE-2024-2564
CVE.ORG link : CVE-2024-2564
JSON object : View
Products Affected
pandax
- pandax
CWE
CWE-24
Path Traversal: '../filedir'
