PT-2022-15679 · Synel · Synel

Published

2022-01-28

·

Updated

2022-02-02

·

CVE-2022-22790

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SYNEL - eharmony (affected versions not specified)
Description The issue allows an attacker to perform a Directory Traversal attack, which is aimed at gaining unauthorized access to the file system. By manipulating the Name parameter, an attacker can return to the root directory and access the host file, exposing sensitive files that users upload.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22790

Affected Products

Synel