{"id":"GHSA-9xhh-3m78-gvgj","summary":"CLSA Directory Traversal vulnerability","details":"Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.\n\nFixes for this issue have been backported to the 5.x, 6.x, and 7.x branches of CSLA. CSLA version 5.5.4 contains a fix. As of time of publication, 6.x and 7.x do not have numbered versions containing the fix but do have fix commits available.","aliases":["CVE-2024-28698"],"modified":"2026-08-24T00:32:40.332963063Z","published":"2024-07-22T18:31:48Z","database_specific":{"nvd_published_at":"2024-07-22T18:15:03Z","cwe_ids":["CWE-22"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-08-02T16:02:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28698"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/pull/3552"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/2c32a5748a0a4bb0159285dfad61d4050e890080"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/445bc609bc117f62cabf49e1462f7a43b0f8f9a2"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/8fbdd8c773bfeb9ba3e52d91b5a664848629b13a"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/f3a5c3474974f60ce3c8ffbd5d91c23a1e397ea4"},{"type":"PACKAGE","url":"https://github.com/MarimerLLC/csla"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/releases/tag/v5.5.4"},{"type":"WEB","url":"https://www.intruder.io/research/path-traversal-and-code-execution-in-csla-net-cve-2024-28698"}],"affected":[{"package":{"name":"Csla","ecosystem":"NuGet","purl":"pkg:nuget/Csla"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.4"}]}],"versions":["5.0.0","5.0.0-R19052204","5.0.0-R19080501","5.0.0-R19082107","5.0.0-R19082803","5.0.0-R19090201","5.0.0-R19091001","5.0.0-R19091005","5.0.0-R19091601","5.0.0-R19091701","5.0.1","5.1.0","5.1.0-R19101002","5.1.0-R19110101","5.1.0-R19110701","5.1.0-R19122302","5.1.0-R20011901","5.1.0-R20012001","5.1.0-R20012201","5.1.0-R20020503","5.1.0-R20020701","5.2.0","5.2.0-R20040904","5.2.0-R20042401","5.2.0-R20042901","5.2.0-R20050802","5.3.0","5.3.0-R20062901","5.3.1","5.3.1-R20082601","5.3.2","5.4.0","5.4.0-R20111002","5.4.0-R20111202","5.4.0-R20113004","5.4.1","5.4.1-R21011901","5.4.2","5.4.2-R21040501","5.5.0","5.5.0-R21070101","5.5.0-R21071901","5.5.1","5.5.1-R21080301","5.5.1-R21082202","5.5.2","5.5.2-R21101501","5.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-9xhh-3m78-gvgj/GHSA-9xhh-3m78-gvgj.json"}},{"package":{"name":"Csla","ecosystem":"NuGet","purl":"pkg:nuget/Csla"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"8.0.0"}]}],"versions":["6.0.0","6.1.0","6.1.0-R22070602","6.2.0","6.2.1","6.2.2","7.0.0","7.0.0-R23042102","7.0.0-R23042601","7.0.0-R23052201","7.0.1","7.0.2","7.0.3","7.0.3-R23113004","7.0.4","7.0.5","7.0.6","7.0.7","8.0.0-R23122103","8.0.0-R24010305","8.0.0-R24012202","8.0.0-R24021201","8.0.0-R24031201","8.0.0-R24031302","8.0.0-R24032503"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-9xhh-3m78-gvgj/GHSA-9xhh-3m78-gvgj.json"}},{"package":{"name":"Csla","ecosystem":"NuGet","purl":"pkg:nuget/Csla"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"8.0.0"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.3","7.0.3-R23113004","7.0.4","7.0.5","7.0.6","7.0.7","8.0.0-R23122103","8.0.0-R24010305","8.0.0-R24012202","8.0.0-R24021201","8.0.0-R24031201","8.0.0-R24031302","8.0.0-R24032503"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-9xhh-3m78-gvgj/GHSA-9xhh-3m78-gvgj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}