PT-2023-7879 · Unknown · Itpison Omicard Edm
Vtim
·
Published
2023-12-14
·
Updated
2023-12-22
·
CVE-2023-48373
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ITPison OMICARD EDM (affected versions not specified)
Description
The issue is related to a path traversal vulnerability within the
FileName parameter in a specific function. This vulnerability can be exploited by an unauthenticated remote attacker to bypass authentication and download arbitrary system files. The vulnerability is associated with incorrect restriction of the directory path name with limited access when processing the FileName parameter.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable function that processes the
FileName parameter to minimize the risk of exploitation. Avoid using the FileName parameter in the affected function until the issue is resolved.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itpison Omicard Edm