Smart eVision has a path traversal... CVE-2022-39034

- AV AC AU C I A
发布: 2022-09-28
修订: 2024-11-21

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息