{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/hsclabs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hsclabs:mailinspector:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2024-34470"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mailinspector (\u003c 5.2.19)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Hsclabs"],"content_html":"\u003cp\u003eHSC Mailinspector versions up to and including 5.2.18 are vulnerable to an unauthenticated path traversal vulnerability (CVE-2024-34470). The issue resides in the '/public/loader.php' script, which fails to properly sanitize the 'path' parameter. An unauthenticated attacker can exploit this flaw to escape the application's web root directory and perform arbitrary file reads on the underlying server. Because the application processes the 'path' parameter without verifying if the requested resource resides within authorized directories, an attacker can access sensitive files such as '/etc/passwd' or application configuration files by supplying specially crafted directory traversal sequences (e.g., '../'). The widespread availability of proof-of-concept exploits on platforms such as GitHub and KitPloit significantly increases the likelihood of exploitation against internet-facing Mailinspector instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Mailinspector instances.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the '/mailinspector/public/loader.php' endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a 'path' query parameter containing traversal sequences (e.g., '../../../../etc/passwd').\u003c/li\u003e\n\u003cli\u003eThe Mailinspector server receives the request and processes the 'loader.php' script.\u003c/li\u003e\n\u003cli\u003eThe script fails to validate the input, allowing the application to traverse outside the intended directory.\u003c/li\u003e\n\u003cli\u003eThe web server reads the contents of the requested file from the filesystem.\u003c/li\u003e\n\u003cli\u003eThe server returns the file content in the HTTP response, allowing the attacker to exfiltrate sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to read any file on the server to which the web application process has access. This can lead to the exposure of credentials, configuration files, system files, and proprietary data. In some cases, this exposure can provide sufficient information for an attacker to escalate privileges or gain full control of the affected server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Hsclabs Mailinspector to version 5.2.19 or later to apply the official vendor patch.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect exploitation attempts targeting the 'path' parameter in 'loader.php'.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for HTTP requests to '/public/loader.php' containing sequences like '..' or directory path patterns, particularly those that do not result in a 404 status.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block requests to the 'loader.php' file containing path traversal characters (e.g., '../', '%2e%2e%2f').\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T09:17:27Z","date_published":"2026-09-05T09:17:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-34470/","summary":"CVE-2024-34470 is an unauthenticated path traversal vulnerability in Hsclabs Mailinspector versions prior to 5.2.19, allowing remote attackers to read arbitrary files from the server filesystem via the 'path' parameter in loader.php.","title":"Unauthenticated Path Traversal in Hsclabs Mailinspector","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-34470/"}],"language":"en","title":"CraftedSignal Threat Feed - Hsclabs","version":"https://jsonfeed.org/version/1.1"}