CVE-2024-22723: Webtrees

Medium severity, CVSS 4.9. EPSS: 0.9% chance of exploitation in the next 30 days.

Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.

Affected products

Published 2024-02-28. Last modified 2026-06-17.