Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I wrote it over the python script shared yesterday. Link: https://github.com/sleep46/CVE-2024-4836_Check/blob/main/CVE-2024-4836_Check.py
https://cert.pl/en/posts/2024/07/CVE-2024-4836/
CERT Polska has received a report about a vulnerability in Edito CMS software and participated in coordination of its disclosure.
Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthorized user. The vulnerability has been assigned CVE-2024-4836 identifier.
The issue affects versions from 3.5 through 3.25. It was removed in releases which dates from 10th of January 2014. Higher versions are not affected. It is possible to disable access to sensitive files by using a modified configuration template provided by the vendor.
Template Validation
I've validated this template locally?
Additional Details (leave it blank if not applicable)
Additional References: