← Back

CVE-2022-39036

nvd nist
Published: Nov 10, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: twcert@cert.org.tw (Secondary)

Description

The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system or disrupt service.

Affected (1)

Products: Flowring: Agentflow
1 product
Agentflow
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0.0.1183.552

Timeline

No history available yet.