{ "id": "CVE-2024-57170", "sourceIdentifier": "cve@mitre.org", "published": "2025-03-18T16:15:25.180", "lastModified": "2025-03-18T16:15:25.180", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The \"fichier_to_delete\" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality." } ], "metrics": {}, "references": [ { "url": "https://themcsam.github.io/posts/so-planing-vulnerabilities/#arbitrary-file-deletion", "source": "cve@mitre.org" } ] }