CVE-2024-34193: LKW199711 Smanga

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.

Affected products

Published 2024-05-20. Last modified 2026-06-17.