Back to Labs
Security Advisory

CVE-2024-25461

About

Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

Weakness (CWE):CWE-22

Rainforest analyst review

Creatio's CRM exposes a component, terrasoft.axd, that can be tricked into serving files from outside its intended path, giving an unauthenticated remote caller a way to read sensitive material off the server. Nothing gets written or executed here; the damage is confidentiality, but on a CRM that can mean configuration secrets, connection strings, or business data.

Directory traversal against a named, well-known endpoint is exactly the kind of thing that gets folded into scanning templates once it's public, precisely because it's cheap to probe and needs no login. The impact stops at reading, so it's not a takeover by itself, but the files it can reach often hand an attacker the credential or the internal path that enables the next stage.

For us the priority signal is internet exposure. A CRM is frequently published for remote sales teams, so we want to know which Creatio instances answer from outside and whether the vulnerable component responds there. Where we can't patch immediately, this is a good candidate for a virtual-patch rule at the proxy that blocks traversal sequences against that endpoint, buying time without waiting on the vendor cycle.

References

Related CVEs

Frequently asked questions

What is CVE-2024-25461?

Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

How severe is CVE-2024-25461?

CVE-2024-25461 carries a CVSS 3.1 base score of 7.5, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 75 out of 100, in the high band.

How is CVE-2024-25461 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity None and availability None.

Which products are affected by CVE-2024-25461?

Public advisories list the following as affected: crm creatio. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-25461?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email