PT-2023-13612 · Unknown · Agevolt Portal

CVE-2022-38485

·

Publicado

2023-10-23

·

Atualizado

2024-10-27

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AgeVolt Portal versions prior to 0.1
Description A directory traversal issue exists that leads to Information Disclosure. A remote authenticated attacker could leverage this issue to read files from any location on the target operating system with web server privileges.
Recommendations For versions prior to 0.1, update to version 0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories on the target operating system to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-38485

Produtos afetados

Agevolt Portal