CVE-2024-58302

Source
https://cve.org/CVERecord?id=CVE-2024-58302
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58302.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58302
Published
2025-12-11T21:40:09.699Z
Modified
2026-08-12T03:51:22.832851450Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
FoF Pretty Mail 1.1.2 Local File Inclusion via Email Template Settings
Details

FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrary server files in email templates. Attackers can exploit the template settings by inserting file inclusion payloads to read sensitive system files like /etc/passwd during email generation.

Database specific
{
    "cwe_ids": [
        "CWE-98"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58302.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/friendsofflarum/pretty-mail

Affected ranges

Type
GIT
Repo
https://github.com/friendsofflarum/pretty-mail
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.1.2"
        },
        {
            "last_affected": "1.1.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58302.json"