In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.
| Score | Percentile |
|---|---|
| 0.75% | 73.08% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-2977-5php-6789 ↗ |
| CVE | CVE-2024-57189 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | erxes | < 1.6.2 | 1.6.2 | — |