{"id":"CVE-2024-28698","aliases":["GHSA-9xhh-3m78-gvgj"],"url":"https://o3.security/vulnerability/CVE-2024-28698","summary":"CLSA Directory Traversal vulnerability","details":"Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.\n\nFixes for this issue have been backported to the 5.x, 6.x, and 7.x branches of CSLA. CSLA version 5.5.4 contains a fix. As of time of publication, 6.x and 7.x do not have numbered versions containing the fix but do have fix commits available.","published":"2024-07-22T00:00:00Z","modified":"2026-08-12T03:51:46.165549407Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Csla","fixedVersion":"5.5.4"},{"ecosystem":"NuGet","name":"Csla","fixedVersion":"8.0.0"},{"ecosystem":"NuGet","name":"Csla","fixedVersion":"8.0.0"}],"fix":{"url":"https://github.com/MarimerLLC/csla/pull/3552","label":"MarimerLLC/csla#3552"},"references":[{"type":"WEB","url":"https://www.intruder.io/research/path-traversal-and-code-execution-in-csla-net-cve-2024-28698"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28698.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28698"},{"type":"FIX","url":"https://github.com/MarimerLLC/csla/pull/3552"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/2c32a5748a0a4bb0159285dfad61d4050e890080"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/445bc609bc117f62cabf49e1462f7a43b0f8f9a2"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/8fbdd8c773bfeb9ba3e52d91b5a664848629b13a"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/commit/f3a5c3474974f60ce3c8ffbd5d91c23a1e397ea4"},{"type":"PACKAGE","url":"https://github.com/MarimerLLC/csla"},{"type":"WEB","url":"https://github.com/MarimerLLC/csla/releases/tag/v5.5.4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.165549407Z"}}