PT-2022-10158 · Unknown · Mdt Autosave
Amir Preminger
·
Published
2022-04-01
·
Updated
2022-04-11
·
CVE-2021-32949
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MDT AutoSave versions prior to v6.02.06
Description
An attacker could utilize a function in MDT AutoSave that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
Recommendations
For versions prior to v6.02.06, update to version v6.02.06 or later to resolve the issue. As a temporary workaround, consider restricting directory traversal and file replacement capabilities until a patch is available.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mdt Autosave