PT-2022-26818 · Arobas Music · Arobas Music Guitar Pro

Pizza Power

·

Published

2022-11-16

·

Updated

2022-11-18

·

CVE-2022-43264

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Arobas Music Guitar Pro for iPad and iPhone versions prior to 1.10.2
Description The issue allows attackers to perform directory traversal and download arbitrary files via a crafted web request.
Recommendations For versions prior to 1.10.2, update to version 1.10.2 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-43264

Affected Products

Arobas Music Guitar Pro