PT-2022-12608 · Taocms · Taocms
Bkfish
·
Published
2022-01-19
·
Updated
2022-01-25
·
CVE-2021-46203
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Taocms version 3.0.2
Description
The issue allows for an arbitrary file read via the
path parameter. This could potentially lead to unauthorized access to sensitive information.Recommendations
For Taocms version 3.0.2, consider restricting access to the
path parameter to minimize the risk of exploitation. Avoid using the path parameter in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taocms