PT-2022-15893 · Amodat · Amodat

Published

2022-06-13

·

Updated

2022-06-27

·

CVE-2022-23167

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue involves an attacker crafting a GET request to the /mobile/downloadfile.aspx endpoint with a Filename parameter set to ../.. /windows/boot.ini, allowing for an unauthenticated Local File Inclusion (LFI) attack. This enables the attacker to access sensitive files on the system without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-23167

Affected Products

Amodat