PT-2023-7879 · Unknown · Itpison Omicard Edm

Vtim

·

Published

2023-12-14

·

Updated

2023-12-22

·

CVE-2023-48373

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ITPison OMICARD EDM (affected versions not specified)
Description The issue is related to a path traversal vulnerability within the FileName parameter in a specific function. This vulnerability can be exploited by an unauthenticated remote attacker to bypass authentication and download arbitrary system files. The vulnerability is associated with incorrect restriction of the directory path name with limited access when processing the FileName parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable function that processes the FileName parameter to minimize the risk of exploitation. Avoid using the FileName parameter in the affected function until the issue is resolved.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-08950
CVE-2023-48373

Affected Products

Itpison Omicard Edm