PT-2022-12608 · Taocms · Taocms

Bkfish

·

Published

2022-01-19

·

Updated

2022-01-25

·

CVE-2021-46203

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Taocms version 3.0.2
Description The issue allows for an arbitrary file read via the path parameter. This could potentially lead to unauthorized access to sensitive information.
Recommendations For Taocms version 3.0.2, consider restricting access to the path parameter to minimize the risk of exploitation. Avoid using the path parameter in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46203

Affected Products

Taocms