xsspresso
xsspresso
Tags/ CVE-2024-41817

CVE-2024-41817

1 writeup tagged with CVE-2024-41817

WebEasyLinux

HTB — Titanic

Flask app path traversal via download endpoint reads arbitrary files including admin credentials. Magick ImageMagick CVE-2024-41817 for root shell.

#Path Traversal#Flask#ImageMagick
Feb 16, 2025HackTheBox