CVE-2024-34523: Inclusive-Design Achecker
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
- Inclusive-Design Achecker: version 1.5 only
Published 2024-05-07. Last modified 2026-06-17.