CVE-2024-45241: Centralsquare Crywolf
High severity, CVSS 7.5. EPSS: 13.6% chance of exploitation in the next 30 days.
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
Affected products
- Centralsquare Crywolf: up to and including 2024_08_09
Published 2024-08-26. Last modified 2026-06-17.