CVE-2024-45440 POC (Proof-of-Concept)

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

Published: 2024-08-29

CVSS: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Download CVE-2024-45440 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check my portfolio here:

https://tlncglobal.com/poc-327-cve-2025-26680/

https://tlncglobal.com/poc-120-cve-2025-52691/

https://tlncglobal.com/poc-373-cve-2025-24383/

https://tlncglobal.com/poc-341-cve-2025-2611/

https://tlncglobal.com/poc-780-cve-2024-52800/