← Back to browse · API

CVE-2023-34096

Severity
MEDIUM
CVSS
6.5
EPSS
0.62682
Risk score
47.94
CISA KEV
No
PoC
No
Published
2023-06-08
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-38204
Products
sni:Thruk < 3.06.2
Sources
euvd EUVD-2023-38204

Description

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (`.`) and the slash (`/`). A fix is available in version 3.06.2.

References