CVE-2024-5334 Scanner

CVE-2024-5334 Scanner - Local File Inclusion vulnerability in Devika AI

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

23 days 9 hours

Scan only one

Domain, IPv4

Toolbox

-

Devika AI is a web application used for web scraping and browser automation.

This vulnerability exists due to improper handling of user input in the snapshot_path parameter. An attacker can exploit this vulnerability to read arbitrary files on the system by crafting a malicious request.

The vulnerability is located in the /api/get-browser-snapshot endpoint of the Devika AI application. The snapshot_path parameter is not properly validated, allowing attackers to specify a path to a file they want to read.

Successful exploitation of this vulnerability could allow an attacker to read sensitive information from the server, such as configuration files or user data. This information could then be used to launch further attacks on the system.

References:

Get started to protecting your Free Full Security Scan