CVE-2024-28335
Estado: AplazadaCrítica (9.1)—
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.85%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-22
Referencias
- https://brave.com/privacy-updates/27-localhost-permission/
- https://cxsecurity.com/issue/WLB-2024030043
- https://getlektor.com/docs/quickstart
- https://github.com/lektor/lektor/pull/1179/commits/8f38b9713d152622b69ff5e3b1e6a0d7bb7fa800
- https://github.com/lektor/lektor/releases/tag/v3.3.11
- https://packetstormsecurity.com/files/177708/Lektor-Static-CMS-3.3.10-Arbitrary-File-Upload-Remote-Code-Execution.html
- https://brave.com/privacy-updates/27-localhost-permission/
- https://cxsecurity.com/issue/WLB-2024030043
- https://getlektor.com/docs/quickstart
- https://github.com/lektor/lektor/pull/1179/commits/8f38b9713d152622b69ff5e3b1e6a0d7bb7fa800
- https://github.com/lektor/lektor/releases/tag/v3.3.11
- https://packetstormsecurity.com/files/177708/Lektor-Static-CMS-3.3.10-Arbitrary-File-Upload-Remote-Code-Execution.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-28335",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-28335",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-06T15:03:17.865791Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:lektor:lektor:*:*:*:*:*:*:*:*"
],
"vendor": "lektor",
"product": "lektor",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.3.11",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-27T06:15:19.447",
"references": [
{
"url": "https://brave.com/privacy-updates/27-localhost-permission/",
"source": "cve@mitre.org"
},
{
"url": "https://cxsecurity.com/issue/WLB-2024030043",
"source": "cve@mitre.org"
},
{
"url": "https://getlektor.com/docs/quickstart",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/lektor/lektor/pull/1179/commits/8f38b9713d152622b69ff5e3b1e6a0d7bb7fa800",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/lektor/lektor/releases/tag/v3.3.11",
"source": "cve@mitre.org"
},
{
"url": "https://packetstormsecurity.com/files/177708/Lektor-Static-CMS-3.3.10-Arbitrary-File-Upload-Remote-Code-Execution.html",
"source": "cve@mitre.org"
},
{
"url": "https://brave.com/privacy-updates/27-localhost-permission/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cxsecurity.com/issue/WLB-2024030043",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://getlektor.com/docs/quickstart",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/lektor/lektor/pull/1179/commits/8f38b9713d152622b69ff5e3b1e6a0d7bb7fa800",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/lektor/lektor/releases/tag/v3.3.11",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://packetstormsecurity.com/files/177708/Lektor-Static-CMS-3.3.10-Arbitrary-File-Upload-Remote-Code-Execution.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the \"lektor server\" command."
},
{
"lang": "es",
"value": "Lektor anterior a 3.3.11 no sanitiza el path traversal de la base de datos. Por lo tanto, los comandos de shell pueden ejecutarse a través de un archivo que se agrega al directorio de plantillas, si el navegador web de la víctima accede a un sitio web que no es de confianza y que usa JavaScript para enviar solicitudes al puerto localhost 5000, y el navegador web se ejecuta en la misma máquina que el Comando \"servidor lector\"."
}
],
"lastModified": "2026-06-17T07:21:20.710",
"sourceIdentifier": "cve@mitre.org"
}