PT-2023-25151 · Unknown · Conacwin Cb
Agustín Picazo
·
Published
2023-10-04
·
Updated
2023-10-05
·
CVE-2023-3512
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ConacWin CB versions 3.8.2.2 and earlier
Description
The issue is a relative path traversal vulnerability that could allow an attacker to perform an arbitrary download of files from the system via the
Download file parameter.Recommendations
For ConacWin CB versions 3.8.2.2 and earlier, consider restricting access to the
Download file parameter until a patch is available. As a temporary workaround, avoid using the Download file parameter in the affected system to minimize the risk of exploitation.Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Conacwin Cb