U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-56509

Change History

New CVE Received from GitHub, Inc. 12/27/2024 11:15:25 AM

Action Type Old Value New Value
Added Description

								
							
							
						
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow attackers to perform local file read (LFR) or path traversal attacks. These vulnerabilities occur when user input is used to construct file paths without adequate sanitization or validation. For example, using file:../../../etc/passwd or file: ///etc/passwd can bypass weak validations and allow unauthorized access to sensitive files. Even though this has been addressed in previous patch, it is still insufficient. This vulnerability is fixed in 0.48.05.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Added CWE

								
							
							
						
CWE-22
Added CWE

								
							
							
						
CWE-200
Added Reference

								
							
							
						
https://github.com/dgtlmoon/changedetection.io/commit/f7e9846c9b40a229813d19cdb66bf60fbe5e6a2a
Added Reference

								
							
							
						
https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-j5vv-6wjg-cfr8