CVE-2024-24398
Critical · CVSS 9.8Stimulsoft Dashboard.JS — Directory Traversal / Path Traversal leading to Remote Code Execution
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-22, CWE-22
Description
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
Search profile — drives PoC discovery
Symbols fileNameSaveDashboard.JSStiDashboardStiReportdesigner/saveviewer/saveapi/save
Keywords CVE-2024-24398Stimulsoft Dashboard.JSdirectory traversalpath traversalfileName parameterSave functionRCEstimulsoft2024.1.2
Versions: < 2024.1.2
Ranked PoCs (3) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 19Ch-Jad/CH-JaDi-Rajput1 needs reviewgh_search
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0trustcves/CVE-2024-24398 needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z