Description


Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.

References



Weaknesses



CWE-22

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-27T21:15:08.407Z

2 years ago

Last modified

2025-03-28T19:15:17.130Z

9 months ago