Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HHIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 1.3
affected
Default status
unaffected
Any version before 9.2.1
affected
Description
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
Problem types
Product status
Any version before 1.3
Any version before 9.2.1
Credits
Michael Heinzl reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-24-326-07