← Back

CVE-2022-28478

nvd nist
Published: Jun 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

Affected (2)

Products: Seeddms: Seeddms
1 product
Seeddms
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Seeddms
Version 5.1.24
Version 6.0.17

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.