Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54663 | Erxes Path Traversal vulnerability |
Github GHSA |
GHSA-2977-5php-6789 | Erxes Path Traversal vulnerability |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Erxes
Erxes erxes |
|
| CPEs | cpe:2.3:a:erxes:erxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Erxes
Erxes erxes |
Tue, 17 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Jun 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Tue, 10 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-17T19:12:52.744Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57189
Updated: 2025-06-10T17:22:37.377Z
Status : Analyzed
Published: 2025-06-10T17:20:09.367
Modified: 2025-06-20T13:08:09.060
Link: CVE-2024-57189
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:14Z
EUVD
Github GHSA