Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Thomas Smits

Researcher fromERNW Enno Rey Netzwerke GmbH
#44402of 53,633
5.9Total CVSS
Vulnerabilities · 1
PT-2022-18681
5.9
2022-03-25
Mendelson · Mendelson Oftp2 · CVE-2022-27906
**Name of the Vulnerable Software and Affected Versions** Mendelson OFTP2 versions prior to 1.1 b43 **Description** The issue allows an attacker to perform a directory traversal attack. To exploit this, the attacker must be aware of one of the configured Odette IDs of the OFTP2 server. This enables the attacker to upload files to the server in locations outside of the intended upload directory. **Recommendations** For Mendelson OFTP2 versions prior to 1.1 b43, update to version 1.1 b43 or later to resolve the issue. As a temporary workaround, consider restricting access to the configured Odette IDs to minimize the risk of exploitation.