{"id":"GHSA-g5p6-3j82-xfm4","summary":"Croogo CMS has a path traversal vulnerability","details":"A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.","aliases":["CVE-2024-42718"],"modified":"2025-12-26T23:41:13.947940Z","published":"2025-12-26T18:30:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-26T23:21:14Z","nvd_published_at":"2025-12-26T17:15:42Z","cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42718"},{"type":"PACKAGE","url":"https://github.com/croogo/croogo"},{"type":"WEB","url":"https://github.com/jacopo1223/jacopo.github/tree/main/CVE-2024-42718"}],"affected":[{"package":{"name":"croogo/croogo","ecosystem":"Packagist","purl":"pkg:composer/croogo/croogo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.0.7"}]}],"versions":["2.3.3","3.0.0","3.0.0-alpha.1","3.0.0-alpha.2","3.0.0-alpha.3","3.0.0-alpha.4","3.0.0-beta.1","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","4.0.0","4.0.0-alpha.2","4.0.0-beta.1","4.0.0-beta.2","4.0.0-beta.3","4.0.0-beta.4","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","v2.0.0","v2.1.0","v2.1.1","v2.1.2","v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.2.4","v2.3.0","v2.3.1","v2.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-g5p6-3j82-xfm4/GHSA-g5p6-3j82-xfm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}