PT-2023-25151 · Unknown · Conacwin Cb
Agustín Picazo
·
Publicado
2023-10-04
·
Atualizado
2023-10-05
·
CVE-2023-3512
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ConacWin CB versions 3.8.2.2 and earlier
Description
The issue is a relative path traversal vulnerability that could allow an attacker to perform an arbitrary download of files from the system via the
Download file parameter.Recommendations
For ConacWin CB versions 3.8.2.2 and earlier, consider restricting access to the
Download file parameter until a patch is available. As a temporary workaround, avoid using the Download file parameter in the affected system to minimize the risk of exploitation.Correção
Relative Path Traversal
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Conacwin Cb