PT-2023-13059 · Unknown · Scriptcase
Toxich4
·
Published
2023-03-27
·
Updated
2025-02-19
·
CVE-2022-32199
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ScriptCase versions 9.9.008 and earlier
Description
The issue allows for Arbitrary File Deletion by an admin via a directory traversal sequence in the
file parameter. This can be exploited through the db convert.php file.Recommendations
For versions 9.9.008 and earlier, consider restricting access to the db convert.php file and the
file parameter to minimize the risk of exploitation. As a temporary workaround, restrict the use of directory traversal sequences in the file parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriptcase