Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
0.0.0 (semver) before 1.2.2
affected
Default status
unaffected
0.0.0 (semver) before 2.4.2
affected
Description
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.
Problem types
CWE-790 Improper Filtering of Special Elements
Product status
0.0.0 (semver) before 1.2.2
0.0.0 (semver) before 2.4.2
Credits
Marvin Ramsperger from SySS GmbH
References
certvde.com/de/advisories/VDE-2026-010