Unrated severityNVD Advisory· Published Dec 11, 2025· Updated Apr 7, 2026
xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php
CVE-2024-58312
Description
xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal characters in HTTP requests.
Affected products
1- xbtitfm/xbtitFMv5Range: 4.1.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51909mitreexploit
- www.vulncheck.com/advisories/xbtitfm-unauthenticated-path-traversal-in-nfogenphpmitrethird-party-advisory
- xbtitfm.eumitreproduct
News mentions
0No linked articles in our index yet.