PT-2022-17075 · Ectouch · Ectouch

Published

2022-02-23

·

Updated

2022-03-03

·

CVE-2022-25098

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ECTouch version 2
Description The issue is related to arbitrary file deletion due to insufficient filtering of the filename parameter. This allows for potential unauthorized access and modification of files.
Recommendations For ECTouch version 2, consider restricting access to the filename parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the filename parameter in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-25098
GHSA-PH62-8768-R87V

Affected Products

Ectouch