PT-2022-18681 · Mendelson · Mendelson Oftp2

Thomas Smits

·

Published

2022-03-25

·

Updated

2022-04-01

·

CVE-2022-27906

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mendelson OFTP2 versions prior to 1.1 b43
Description The issue allows an attacker to perform a directory traversal attack. To exploit this, the attacker must be aware of one of the configured Odette IDs of the OFTP2 server. This enables the attacker to upload files to the server in locations outside of the intended upload directory.
Recommendations For Mendelson OFTP2 versions prior to 1.1 b43, update to version 1.1 b43 or later to resolve the issue. As a temporary workaround, consider restricting access to the configured Odette IDs to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27906

Affected Products

Mendelson Oftp2