Home
HIGH: 8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 7.6.0
affected
Description
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to remote code execution (RCE).
Problem types
CWE-23 Relative Path Traversal
Product status
Any version before 7.6.0
References
servicedesk.logpoint.com/...tes-Allows-Remote-Code-Execution
servicedesk.logpoint.com/...s/7201103730845-Product-Security