PT-2022-16559 · Unknown · Aceweb Online Portal

Published

2022-05-27

·

Updated

2022-06-11

·

CVE-2022-24241

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ACEweb Online Portal version 3.5.065
Description The issue is related to an External Controlled File Path and Name vulnerability. This vulnerability can be exploited via the txtFilePath parameter in the "attachments.awp" endpoint.
Recommendations For ACEweb Online Portal version 3.5.065, avoid using the txtFilePath parameter in the attachments.awp endpoint until a fix is available. Consider restricting access to the attachments.awp endpoint to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24241

Affected Products

Aceweb Online Portal