id: CVE-2024-40348 info: name: Bazarr < 1.4.3 - Arbitrary File Read author: securityforeveryone severity: high description: | Bazarr 1.4.3 and earlier versions have a arbitrary file read vulnerability. reference: - https://github.com/4rdr/proofs/blob/main/info/Bazaar_1.4.3_File_Traversal_via_Filename.md - https://www.bazarr.media/ - https://github.com/bigb0x/CVE-2024-40348 classification: epss-score: 0.00043 epss-percentile: 0.09329 metadata: verified: true max-request: 2 vendor: morpheus65535 product: bazarr fofa-query: title=="Bazarr" && icon_hash="-1983413099" tags: cve,cve2024,bazarr,lfi flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/login" matchers: - type: word part: body words: - '