CVE-2024-11123 | 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3 /crm/data/pdf.php url path traversal
A vulnerability categorized as critical has been discovered in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Impacted is an unknown function of the file /crm/data/pdf.php. Such manipulation of the argument url with the input ../config.inc.php leads to path traversal.
This vulnerability is referenced as CVE-2024-11123. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.