PT-2022-27420 · Ironman · Powershell Universal

Thierry Viaccoz

·

Published

2022-11-14

·

Updated

2022-11-16

·

CVE-2022-45184

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ironman Software PowerShell Universal versions prior to 3.5.3 Ironman Software PowerShell Universal versions prior to 3.4.7
Description The issue allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to particular endpoints in the web server. This is due to directory traversal outside of the configuration directory in the Web Server.
Recommendations For versions prior to 3.5.3, update to version 3.5.3 or later. For versions prior to 3.4.7, update to version 3.4.7 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45184

Affected Products

Powershell Universal