CVE-2024-5334 Scanner
CVE-2024-5334 Scanner - Local File Inclusion vulnerability in Devika AI
Short Info
Level
High
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
23 days 9 hours
Scan only one
Domain, IPv4
Toolbox
-
Devika AI is a web application used for web scraping and browser automation.
This vulnerability exists due to improper handling of user input in the snapshot_path
parameter. An attacker can exploit this vulnerability to read arbitrary files on the system by crafting a malicious request.
The vulnerability is located in the /api/get-browser-snapshot
endpoint of the Devika AI application. The snapshot_path
parameter is not properly validated, allowing attackers to specify a path to a file they want to read.
Successful exploitation of this vulnerability could allow an attacker to read sensitive information from the server, such as configuration files or user data. This information could then be used to launch further attacks on the system.
References: