PT-2023-13612 · Unknown · Agevolt Portal

Published

2023-10-23

·

Updated

2024-10-27

·

CVE-2022-38485

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AgeVolt Portal versions prior to 0.1
Description A directory traversal issue exists that leads to Information Disclosure. A remote authenticated attacker could leverage this issue to read files from any location on the target operating system with web server privileges.
Recommendations For versions prior to 0.1, update to version 0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories on the target operating system to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-38485

Affected Products

Agevolt Portal