PT-2022-24878 · Melisplatform · Melis-Asset-Manager
Published
2022-10-11
·
Updated
2022-10-14
·
CVE-2022-39296
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
melisplatform/melis-asset-manager versions prior to 5.0.1
Description
The issue allows attackers to read arbitrary files, leading to the disclosure of sensitive information. This can be done without requiring authentication. The problem was addressed by restricting access to files to intended directories only. Users should upgrade to a version that includes this fix.
Recommendations
For versions prior to 5.0.1, upgrade to melisplatform/melis-asset-manager version 5.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories until the upgrade can be applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melis-Asset-Manager