Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Happi0O

#37319of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2022-24571
7.5
2022-08-27
Zaver · Zaver · CVE-2022-38794
**Name of the Vulnerable Software and Affected Versions** Zaver versions through 2020-12-15 **Description** The issue allows directory traversal via the GET /.. substring. This can be exploited through the "GET /.. substring" API endpoint. **Recommendations** For versions through 2020-12-15, consider restricting access to the API endpoint "GET /.." to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.