CVE-2022-27192
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
Affected (1)
Products: Asseco: Dvs Avilys
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.58 |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory
Timeline
No history available yet.