← Back

CVE-2022-31324

nvd nist
Published: Sep 13, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.

Affected (3)

1 product
Wapples
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Pentasecurity
From 4.0.0 to 6.0.r3.4.10
Version v6.0.r3.4.10
Version v6.0.r3.4.10 hotfix1

Timeline

No history available yet.