PT-2022-4185 · Unknown+1 · Passwork On-Premise Edition+1
Arian Rakhimi
·
Published
2022-03-23
·
Updated
2022-08-17
·
CVE-2022-25267
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Passwork On-Premise Edition versions prior to 4.6.13
Description
The issue is related to incorrect restriction of the path name to a directory with limited access. This allows a remote attacker to upload arbitrary files to the system. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Passwork On-Premise Edition versions prior to 4.6.13, update to version 4.6.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the migration/uploadExportFile functionality to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passwork
Passwork On-Premise Edition